Skip to content

Conversation

@renovate
Copy link

@renovate renovate bot commented Oct 11, 2023

This PR contains the following updates:

Package Change Age Confidence
org.bouncycastle:bcpkix-jdk18on (source) 1.791.83 age confidence
org.wiremock.integrations:wiremock-spring-boot 3.10.03.10.6 age confidence
io.jsonwebtoken:jjwt-jackson 0.12.60.13.0 age confidence
io.jsonwebtoken:jjwt-impl 0.12.60.13.0 age confidence
io.jsonwebtoken:jjwt-api 0.12.60.13.0 age confidence

Release Notes

wiremock/wiremock-spring-boot (org.wiremock.integrations:wiremock-spring-boot)

v3.10.6

Compare Source

🚀 New features and improvements

📦 Dependency updates

✍ Other changes

jwtk/jjwt (io.jsonwebtoken:jjwt-jackson)

v0.13.0

Compare Source

This is the last minor JJWT release branch that will support Java 7. Any necessary emergency bug fixes will be fixed in subsequent 0.13.x patch releases, but all new development, including Java 8 compatible changes, will be in the next minor (0.14.0) release.

All future JJWT major and minor versions ( 0.14.0 and later) will require Java 8 or later.

This 0.13.0 minor release has only one change:

  • The previously private JacksonDeserializer(ObjectMapper objectMapper, Map<String, Class<?>> claimTypeMap) constructor is now public for those that want register a claims
    type converter on their own specified ObjectMapper instance. See Issue 914.

v0.12.7

Compare Source

This patch release:

  • Adds a new Maven BOM, useful for multi-module projects. See Issue 967.

  • Allows the JwtParserBuilder to have empty nested algorithm collections, effectively disabling the parser's associated feature:

    • Emptying the zip() nested collection disables JWT decompression.
    • Emptying the sig() nested collection disables JWS mac/signature verification (i.e. all JWSs will be unsupported/rejected).
    • Emptying either the enc() or key() nested collections disables JWE decryption (i.e. all JWEs will be unsupported/rejected)

    See Issue 996.

  • Fixes bug 961 where JwtParserBuilder nested collection builders were not correctly replacing algorithms with the same id.

  • Ensures a JwkSet's keys collection is no longer entirely secret/redacted by default. This was an overzealous default that was unnecessarily restrictive; the keys collection itself should always be public, and each individual key within should determine which fields should be redacted when printed. See Issue 976.

  • Improves performance slightly by ensuring all jjwt-api utility methods that create *Builder instances (Jwts.builder(), Jwts.parserBuilder(), Jwks.builder(), etc) no longer use reflection.

    Instead,static factories are created via reflection only once during initial jjwt-api classloading, and then *Builders are created via standard instantiation using the new operator thereafter. This also benefits certain environments that may not have ideal ClassLoader implementations (e.g. Tomcat in some cases).

    NOTE: because this changes which classes are loaded via reflection, any environments that must explicitly reference reflective class names (e.g. GraalVM applications) will need to be updated to reflect the new factory class names.

    See Issue 988.

  • Upgrades the Gson dependency to 2.11.0

  • Upgrades the BouncyCastle dependency to 1.78.1


Configuration

📅 Schedule: Branch creation - At any time (no schedule defined), Automerge - At any time (no schedule defined).

🚦 Automerge: Enabled.

Rebasing: Whenever PR is behind base branch, or you tick the rebase/retry checkbox.

👻 Immortal: This PR will be recreated if closed unmerged. Get config help if that's undesired.


  • If you want to rebase/retry this PR, check this box

This PR was generated by Mend Renovate. View the repository job log.

@renovate renovate bot force-pushed the renovate/all-maven-test-deps branch from 2079a95 to 5e7dba6 Compare October 15, 2023 08:30
@codecov
Copy link

codecov bot commented Oct 15, 2023

Codecov Report

All modified and coverable lines are covered by tests ✅

Project coverage is 67.40%. Comparing base (b7f3cbc) to head (cff2cc7).
Report is 21 commits behind head on master.

Current head cff2cc7 differs from pull request most recent head 2e19abb

Please upload reports for the commit 2e19abb to get more accurate results.

Additional details and impacted files
@@             Coverage Diff              @@
##             master      #42      +/-   ##
============================================
+ Coverage     65.13%   67.40%   +2.26%     
- Complexity       47       57      +10     
============================================
  Files            18       17       -1     
  Lines           218      227       +9     
  Branches         11       17       +6     
============================================
+ Hits            142      153      +11     
  Misses           73       73              
+ Partials          3        1       -2     

☔ View full report in Codecov by Sentry.
📢 Have feedback on the report? Share it here.

@renovate renovate bot force-pushed the renovate/all-maven-test-deps branch from 5e7dba6 to 9ee7d3a Compare October 19, 2023 10:38
@renovate renovate bot force-pushed the renovate/all-maven-test-deps branch from 9ee7d3a to d839bb3 Compare December 19, 2023 05:19
@renovate renovate bot force-pushed the renovate/all-maven-test-deps branch 2 times, most recently from 306b18c to 627a0c6 Compare January 30, 2024 20:36
@renovate renovate bot force-pushed the renovate/all-maven-test-deps branch from 627a0c6 to cff2cc7 Compare February 2, 2024 08:20
@renovate renovate bot force-pushed the renovate/all-maven-test-deps branch 3 times, most recently from 9c4b2ab to 2e19abb Compare June 27, 2024 12:43
@renovate renovate bot force-pushed the renovate/all-maven-test-deps branch from 2e19abb to a8afbbe Compare July 11, 2024 23:40
@renovate renovate bot force-pushed the renovate/all-maven-test-deps branch from a8afbbe to 9436ce1 Compare October 31, 2024 15:50
@renovate renovate bot force-pushed the renovate/all-maven-test-deps branch 2 times, most recently from 5533a1e to 745385f Compare December 4, 2024 23:52
@renovate renovate bot force-pushed the renovate/all-maven-test-deps branch from 745385f to 8f055bd Compare January 24, 2025 10:31
@renovate renovate bot force-pushed the renovate/all-maven-test-deps branch 2 times, most recently from 74c01a0 to 12999e8 Compare February 10, 2025 15:21
@renovate renovate bot force-pushed the renovate/all-maven-test-deps branch from 12999e8 to 95db9f3 Compare March 19, 2025 23:51
@renovate renovate bot force-pushed the renovate/all-maven-test-deps branch 2 times, most recently from 3c0ca5b to 8c0a562 Compare June 6, 2025 17:21
@renovate renovate bot force-pushed the renovate/all-maven-test-deps branch 3 times, most recently from 9172a75 to afdc6e8 Compare June 23, 2025 10:22
@renovate renovate bot force-pushed the renovate/all-maven-test-deps branch from afdc6e8 to 55b186f Compare August 6, 2025 15:08
@renovate renovate bot force-pushed the renovate/all-maven-test-deps branch 2 times, most recently from 98b7edd to b022e9c Compare August 19, 2025 12:02
@renovate renovate bot force-pushed the renovate/all-maven-test-deps branch from b022e9c to 1ada8f5 Compare August 23, 2025 23:53
@renovate renovate bot force-pushed the renovate/all-maven-test-deps branch from 1ada8f5 to dbb00a3 Compare September 3, 2025 14:13
@renovate renovate bot force-pushed the renovate/all-maven-test-deps branch from dbb00a3 to e3eb35d Compare September 18, 2025 15:55
@renovate renovate bot force-pushed the renovate/all-maven-test-deps branch from e3eb35d to 2e4d16b Compare November 1, 2025 06:28
@renovate renovate bot force-pushed the renovate/all-maven-test-deps branch from 2e4d16b to e101129 Compare November 26, 2025 12:12
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant