Skip to content

Bump the all-dependencies group with 8 updates - #728

Open
dependabot[bot] wants to merge 1 commit into
masterfrom
dependabot/gradle/all-dependencies-21e444d346
Open

dependabot[bot] wants to merge 1 commit into
masterfrom
dependabot/gradle/all-dependencies-21e444d346

Conversation

@dependabot

@dependabot dependabot Bot commented on behalf of github Oct 1, 2026

Copy link
Copy Markdown
Contributor

Bumps the all-dependencies group with 8 updates:

Package From To
gradle-wrapper 9.7.1 9.8.0
io.netty:netty-all 4.0.20.Final 4.2.18.Final
com.google.guava:guava 17.0 23.0
com.velocitypowered:velocity-native 3.4.0-SNAPSHOT 4.2.0
org.spigotmc:spigot-api 1.12.2-R0.1-SNAPSHOT 26.2-R0.1-SNAPSHOT
net.fabricmc:fabric-loader 0.11.3 0.19.5
org.apache.logging.log4j:log4j-api 2.17.1 2.26.1
com.velocitypowered:velocity-api 3.4.0 4.2.0

Updates gradle-wrapper from 9.7.1 to 9.8.0

Release notes

Sourced from gradle-wrapper's releases.

9.8.0

The Gradle team is excited to announce Gradle 9.8.0.

Here are the highlights of this release:

  • Java 27 support
  • Maven mirror settings reuse
  • Linked problem locations in build output

Read the Release Notes

We would like to thank the following community members for their contributions to this release of Gradle: Aman Gautam, Björn Kautler, Eng Zer Jun, Hashim Khan, Julian Krannich, KBS, Labh R Jethe, Mark Dodgson, Maxim, monkey, nataphon-ktsystems, Paul King, Qiu Tian, rg_sandesh, Roberto Perez Alcolea, Sean, Zongle Wang.

Upgrade instructions

Switch your build to use Gradle 9.8.0 by updating your wrapper:

./gradlew :wrapper --gradle-version=9.8.0 && ./gradlew :wrapper

See the Gradle 9.x upgrade guide to learn about deprecations, breaking changes and other considerations when upgrading.

For Java, Groovy, Kotlin and Android compatibility, see the full compatibility notes.

Reporting problems

If you find a problem with this release, please file a bug on GitHub Issues adhering to our issue guidelines. If you're not sure you're encountering a bug, please use the forum.

We hope you will build happiness with Gradle, and we look forward to your feedback via Twitter or on GitHub.

9.8.0 RC3

The Gradle team is excited to announce Gradle 9.8.0 RC3.

Here are the highlights of this release:

... (truncated)

Commits
  • a927be5 Add the Develocity plugin back to the Android smoke tests (#39273)
  • eaee500 Add the Develocity plugin back to the Android smoke tests
  • 189b672 Route everything still hitting Maven Central through the mirror (#39257)
  • 36b1814 Add back mavenCentral to doc snippets
  • 2740c2d Update Gradle wrapper to version 9.8.0-rc-3 (#39264)
  • 2099383 Update Gradle wrapper to version 9.8.0-rc-3
  • c80202f Route everything still hitting Maven Central through the mirror
  • 3f6a534 Fix when a best practice was introduced (#39253)
  • 9efc9ed Fix when a best practice was introduced
  • 459e143 Route integration test dependencies through the repository mirror (#39239)
  • Additional commits viewable in compare view

Updates io.netty:netty-all from 4.0.20.Final to 4.2.18.Final

Release notes

Sourced from io.netty:netty-all's releases.

netty-4.2.18.Final

Security fixes

  • CVE-2026-XXXXX : unbounded resource usage in io.netty:netty-codec-http (SPDY)
  • CVE-2026-XXXXX : unbounded resource usage in io.netty:netty-codec-http (HTTP/1.1)
  • CVE-2026-XXXXX : denial of service vector in io.netty:netty-codec-http2
  • CVE-2026-XXXXX : improper certificate validation in io.netty:netty-handler-ssl-ocsp
  • CVE-2026-XXXXX : memory leak in io.netty:netty-codec-stomp
  • CVE-2026-XXXXX : unbounded resource usage in io.netty:netty-codec-http
  • CVE-2026-XXXXX : improper header validation in io.netty:netty-codec-http3
  • CVE-2026-XXXXX : denial of service vector in io.netty:netty-codec-stomp
  • CVE-2026-XXXXX : parser desync/response smuggling in io.netty:netty-codec-memcache
  • CVE-2026-XXXXX : unbounded resource usage in io.netty:netty-codec-http3
  • CVE-2026-XXXXX : unbounded resource usage in io.netty:netty-codec-http3
  • CVE-2026-XXXXX : unbounded resource usage in io.netty:netty-codec-http3
  • CVE-2026-XXXXX : improper header validation in io.netty:netty-codec-http
  • CVE-2026-XXXXX : unbounded resource usage in io.netty:netty-codec-smtp
  • CVE-2026-XXXXX : memory leak in io.netty:netty-codec-haproxy
  • CVE-2026-XXXXX : request smuggling in io.netty:netty-codec-http (RTSP)
  • CVE-2026-XXXXX : request smuggling in io.netty:netty-codec-http (HTTP/1)
  • CVE-2026-XXXXX : improper header validation in io.netty:netty-codec-http2
  • CVE-2026-XXXXX : improper header validation in io.netty:netty-codec-http (HTTP/1)
  • CVE-2026-XXXXX : improper header validation in io.netty:netty-codec-http3
  • CVE-2026-XXXXX : improper header validation in io.netty:netty-codec-http3 and in io.netty:netty-codec-http2
  • CVE-2026-XXXXX : improper header validation in io.netty:netty-codec-http2
  • CVE-2026-XXXXX : improper hostname verification in io.netty:netty-codec-classes-quic
  • CVE-2026-XXXXX : unbounded resource usage in io.netty:netty-codec-redis
  • CVE-2026-XXXXX : improper header validation in io.netty:netty-codec-http (HTTP/1.1)
  • CVE-2026-XXXXX : request smuggling vector in io.netty:netty-codec-http (HTTP/1.1)
  • CVE-2026-XXXXX : unbounded resource usage in io.netty:netty-codec-mqtt
  • CVE-2026-XXXXX : improper CRLF neutralization in io.netty:netty-codec-smtp
  • CVE-2026-XXXXX : improper certificate validation in io.netty:netty-handler-ssl-ocsp
  • CVE-2026-XXXXX : improper header validation in io.netty:netty-codec-http2

Compatibility Notes

A number of security fixes have added additional validation and impose new resource usage limits, which may cause existing workloads to fail or be rejected. We recommend that you test your systems thoroughly as part of your Netty upgrade.

Two specific changes are worth calling out:

QUIC now explicitly requires X509ExtendedTrustManager when hostname verification is enabled. Previously, when configuring QUIC with an endpoint identification algorithm and an X509TrustManager, hostname verification would be silently skipped. This is now considered a misconfiguration and an exception will be thrown.

HTTP/2 header value validation is now enabled by default. HTTP/2 header name validation has always been enabled by default, with an option to disable it, but HTTP/2 header value validation has been disabled by default until now. Configuration options still exist to disable this, but validation of HTTP header names and values are now both opt-in by default rather than opt-out.

What's Changed

... (truncated)

Commits
  • 2521f49 [maven-release-plugin] prepare release netty-4.2.18.Final
  • 6fd5327 HTTP/1 absolute-form Host mismatch is translated to HTTP/3 :authority, overri...
  • c44a052 SPDY: SpdySessionHandler must limit the concurrent streams
  • 374d965 HTTP: Limit the maximum number of concurrent pipelined requests
  • 7e8b325 HTTP/2: Limit HPACK encoding table size
  • e3ebf70 OCSP: Correctly handle that nextUpdate is optional
  • 5388535 STOMP: Correctly release partial content on handler removal
  • 3a80f5a WebSockets: Enforce a limit for the max pipelined requests in WebSocketServer...
  • 1b6ea48 HTTP3: Correctly handle ":authority" and "host" headers
  • 3630659 STOMP codec content-length long-to-int truncation causes infinite decode loop...
  • Additional commits viewable in compare view

Updates com.google.guava:guava from 17.0 to 23.0

Release notes

Sourced from com.google.guava:guava's releases.

23.0

Final Guava 23.0 release.

23.0-rc1

First Guava 23.0 release candidate.

22.0

Final Guava 22.0 release.

22.0-rc1

First release candidate for Guava 22.0.

21.0

Final Guava 21.0 release.

This release requires Java 8.

21.0-rc2

Second release candidate for Guava 21.0.

This release candidate fixes a small issue with rc1; a number of methods that create Collectors took Guava's functional types (e.g. base.Function) as parameters rather than the java.util.function equivalent.

This release requires Java 8.

21.0-rc1

First release candidate for Guava 21.0.

This release requires Java 8.

20.0

Final Guava 20.0 release.

20.0-rc1

First release candidate for Guava 20.0.

Commits
  • b48cdeb Set version numbers to 23.0
  • 6dae21f Remove some methods that are scheduled for removal in 23.0, along with one th...
  • 22da091 Rollforward [] which was rolled back in [] because it
  • b87e1f1 Automated g4 rollback of changelist 162220754.
  • 44b9081 Set version numbers to 23.0-rc1
  • ee12894 Implement ByteSource.asCharSource(charset).read() using the decoding string c...
  • 71b5b85 Add submitAsync and scheduleAsync methods, to ease the deprecation of Futures...
  • b6c86db Short-circuit null check in Throwables#lazyStackTraceIsLazy
  • dd78480 Update Public Suffix List.
  • 1d7f652 Add @​SafeVarargs to Predicates.and(Predicate<? super T>...).
  • Additional commits viewable in compare view

Updates com.velocitypowered:velocity-native from 3.4.0-SNAPSHOT to 4.2.0

Commits

Updates org.spigotmc:spigot-api from 1.12.2-R0.1-SNAPSHOT to 26.2-R0.1-SNAPSHOT

Updates net.fabricmc:fabric-loader from 0.11.3 to 0.19.5

Updates org.apache.logging.log4j:log4j-api from 2.17.1 to 2.26.1

Updates com.velocitypowered:velocity-api from 3.4.0 to 4.2.0

Commits

Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting @dependabot rebase.


Dependabot commands and options

You can trigger Dependabot actions by commenting on this PR:

  • @dependabot rebase will rebase this PR
  • @dependabot recreate will recreate this PR, overwriting any edits that have been made to it
  • @dependabot show <dependency name> ignore conditions will show all of the ignore conditions of the specified dependency
  • @dependabot ignore <dependency name> major version will close this group update PR and stop Dependabot creating any more for the specific dependency's major version (unless you unignore this specific dependency's major version or upgrade to it yourself)
  • @dependabot ignore <dependency name> minor version will close this group update PR and stop Dependabot creating any more for the specific dependency's minor version (unless you unignore this specific dependency's minor version or upgrade to it yourself)
  • @dependabot ignore <dependency name> will close this group update PR and stop Dependabot creating any more for the specific dependency (unless you unignore this specific dependency or upgrade to it yourself)
  • @dependabot unignore <dependency name> will remove all of the ignore conditions of the specified dependency
  • @dependabot unignore <dependency name> <ignore condition> will remove the ignore condition of the specified dependency and ignore conditions

Bumps the all-dependencies group with 8 updates:

| Package | From | To |
| --- | --- | --- |
| [gradle-wrapper](https://github.com/gradle/gradle) | `9.7.1` | `9.8.0` |
| [io.netty:netty-all](https://github.com/netty/netty) | `4.0.20.Final` | `4.2.18.Final` |
| [com.google.guava:guava](https://github.com/google/guava) | `17.0` | `23.0` |
| [com.velocitypowered:velocity-native](https://github.com/PaperMC/Velocity) | `3.4.0-SNAPSHOT` | `4.2.0` |
| org.spigotmc:spigot-api | `1.12.2-R0.1-SNAPSHOT` | `26.2-R0.1-SNAPSHOT` |
| net.fabricmc:fabric-loader | `0.11.3` | `0.19.5` |
| org.apache.logging.log4j:log4j-api | `2.17.1` | `2.26.1` |
| [com.velocitypowered:velocity-api](https://github.com/PaperMC/Velocity) | `3.4.0` | `4.2.0` |


Updates `gradle-wrapper` from 9.7.1 to 9.8.0
- [Release notes](https://github.com/gradle/gradle/releases)
- [Commits](gradle/gradle@v9.7.1...v9.8.0)

Updates `io.netty:netty-all` from 4.0.20.Final to 4.2.18.Final
- [Release notes](https://github.com/netty/netty/releases)
- [Commits](netty/netty@netty-4.0.20.Final...netty-4.2.18.Final)

Updates `com.google.guava:guava` from 17.0 to 23.0
- [Release notes](https://github.com/google/guava/releases)
- [Commits](google/guava@v17.0...v23.0)

Updates `com.velocitypowered:velocity-native` from 3.4.0-SNAPSHOT to 4.2.0
- [Commits](https://github.com/PaperMC/Velocity/commits)

Updates `org.spigotmc:spigot-api` from 1.12.2-R0.1-SNAPSHOT to 26.2-R0.1-SNAPSHOT

Updates `net.fabricmc:fabric-loader` from 0.11.3 to 0.19.5

Updates `org.apache.logging.log4j:log4j-api` from 2.17.1 to 2.26.1

Updates `com.velocitypowered:velocity-api` from 3.4.0 to 4.2.0
- [Commits](https://github.com/PaperMC/Velocity/commits)

---
updated-dependencies:
- dependency-name: gradle-wrapper
  dependency-version: 9.8.0
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: all-dependencies
- dependency-name: io.netty:netty-all
  dependency-version: 4.2.18.Final
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: all-dependencies
- dependency-name: com.google.guava:guava
  dependency-version: '23.0'
  dependency-type: direct:production
  update-type: version-update:semver-major
  dependency-group: all-dependencies
- dependency-name: com.velocitypowered:velocity-native
  dependency-version: 4.2.0
  dependency-type: direct:production
  update-type: version-update:semver-major
  dependency-group: all-dependencies
- dependency-name: org.spigotmc:spigot-api
  dependency-version: 26.2-R0.1-SNAPSHOT
  dependency-type: direct:production
  dependency-group: all-dependencies
- dependency-name: net.fabricmc:fabric-loader
  dependency-version: 0.19.5
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: all-dependencies
- dependency-name: org.apache.logging.log4j:log4j-api
  dependency-version: 2.26.1
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: all-dependencies
- dependency-name: com.velocitypowered:velocity-api
  dependency-version: 4.2.0
  dependency-type: direct:production
  update-type: version-update:semver-major
  dependency-group: all-dependencies
...

Signed-off-by: dependabot[bot] <support@github.com>
@dependabot dependabot Bot added dependencies Pull requests that update a dependency file java Pull requests that update java code labels Oct 1, 2026
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

dependencies Pull requests that update a dependency file java Pull requests that update java code

Projects

None yet

Development

Successfully merging this pull request may close these issues.

0 participants