Uploaded image for project: 'Quarkus'
  1. Quarkus
  2. QUARKUS-7330

Bump org.assertj:assertj-core from 3.27.6 to 3.27.7

XMLWordPrintable

    • Icon: Component Upgrade Component Upgrade
    • Resolution: Unresolved
    • Icon: Major Major
    • 3.20.6.GA
    • None
    • team/eng
    • None

      Bumps org.assertj:assertj-core from 3.27.6 to 3.27.7.

      Release notes
      Sourced from org.assertj:assertj-core's releases.

      v3.27.7
      πŸ”’ Security
      Core

      Fix XXE vulnerability in isXmlEqualTo assertion (CVE-2026-24400)

      See GHSA-rqfh-9r24-8c9r for details; many thanks to @​wxt201 and @​Song-Li for responsibly reporting it!

      🚫 Deprecated
      Core

      Deprecate XmlStringPrettyFormatter with no replacement

      πŸ› Bug Fixes
      Guava

      Navigation to assertj-core or guava types from assertj-guava Javadoc site has unnecessary header #3478

      πŸ”¨ Dependency Upgrades
      Core

      Upgrade to Byte Buddy 1.18.3
      Upgrade to JUnit BOM 5.14.1

      Guava

      Upgrade to Guava 33.5.0-jre

      Commits

      e840716 [maven-release-plugin] prepare release assertj-build-3.27.7
      85ca7eb Deprecate XmlStringPrettyFormatter
      77081dc Merge commit from fork
      b68fc24 Bump github/codeql-action from 4.31.9 to 4.31.10 in the github-actions group ...
      0cf5bb6 Bump kotlin.version from 2.1.0 to 2.2.21
      d393ef1 Abort tests when symbolic links cannot be created (#3788)
      2212433 Add IntelliJ custom inspection for test class names
      5717d02 Update JetBrains icon
      a8ec20b Add icon for JetBrains products
      c05fb3d Bump Maven to 3.9.12 and Wrapper to 3.3.4
      Additional commits viewable in compare view

      You can trigger a rebase of this PR by commenting @dependabot rebase.

      Dependabot commands and options

      You can trigger Dependabot actions by commenting on this PR:

      @dependabot rebase will rebase this PR
      @dependabot recreate will recreate this PR, overwriting any edits that have been made to it
      @dependabot merge will merge this PR after your CI passes on it
      @dependabot squash and merge will squash and merge this PR after your CI passes on it
      @dependabot cancel merge will cancel a previously requested merge and block automerging
      @dependabot reopen will reopen this PR if it is closed
      @dependabot close will close this PR and stop Dependabot recreating it. You can achieve the same result by closing it manually
      @dependabot show <dependency name> ignore conditions will show all of the ignore conditions of the specified dependency
      @dependabot ignore this major version will close this PR and stop Dependabot creating any more for this major version (unless you reopen the PR or upgrade to it yourself)
      @dependabot ignore this minor version will close this PR and stop Dependabot creating any more for this minor version (unless you reopen the PR or upgrade to it yourself)
      @dependabot ignore this dependency will close this PR and stop Dependabot creating any more for this dependency (unless you reopen the PR or upgrade to it yourself)

              jmartisk@redhat.com Jan Martiska
              msochure@redhat.com Miroslav Sochurek
              Votes:
              0 Vote for this issue
              Watchers:
              1 Start watching this issue

                Created:
                Updated: