Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

build(deps): bump com.github.spotbugs:spotbugs-annotations from 4.8.3 to 4.8.4 #1901

Conversation

dependabot[bot]
Copy link
Contributor

@dependabot dependabot bot commented on behalf of github Apr 8, 2024

Bumps com.github.spotbugs:spotbugs-annotations from 4.8.3 to 4.8.4.

Changelog

Sourced from com.github.spotbugs:spotbugs-annotations's changelog.

4.8.4 - 2024-04-07

Fixed

  • Fix FP in SE_PREVENT_EXT_OBJ_OVERWRITE when the if statement checking for null value, checking multiple variables or the method exiting in the if branch with an exception. (#2750)
  • Fix possible null value in taxonomies of SARIF output (#2744)
  • Fix executionSuccessful flag in SARIF report being set to false when bugs were found (#2116)
  • Move information contained in the SARIF property exitSignalName to exitCodeDescription (#2739)
  • Do not report SE_NO_SERIALVERSIONID or other serialization issues for records (#2793)
  • Added support for CONSTANT_Dynamic (#2759)
  • Ignore generic variable types when looking for BC_UNCONFIRMED_CAST_OF_RETURN_VALUE (#1219)
  • Do not report BC_UNCONFIRMED_CAST for Java 21's type switches (#2813)
  • Remove AppleExtension library (note: menus slightly changed) (#2823)
  • Fix false positive NP_NULL_ON_SOME_PATH_FROM_RETURN_VALUE even if Objects.requireNonNull is used. (#651, #456)
  • Fixed error preventing SpotBugs from reporting FE_FLOATING_POINT_EQUALITY (#2843)
  • Fixed NP_LOAD_OF_KNOWN_NULL_VALUE and RCN_REDUNDANT_NULLCHECK_OF_NULL_VALUE false positives in try-with-resources generated finally blocks (#2844)
  • Do not report DLS_DEAD_LOCAL_STORE for Java 21's type switches (#2828)
  • Update UnreadFields detector to ignore warnings for fields with certain annotations (#574)
  • Do not report UWF_FIELD_NOT_INITIALIZED_IN_CONSTRUCTOR for fields initialized in method annotated with @​PostConstruct, @​BeforeEach, etc. (#2872 #2870 #453)
  • Do not report DLS_DEAD_LOCAL_STORE for Hibernate bytecode enhancements (#2865)
  • Fixed NP_NULL_ON_SOME_PATH_FROM_RETURN_VALUE false positives due to source code formatting (#2874)
  • Added more nullability annotations in TypeQualifierResolver (#2558 #2694)
  • Improved the bug description for VA_FORMAT_STRING_USES_NEWLINE when using text blocks, check the usage of String.formatted() (#2881)
  • Fixed crash in ValueRangeAnalysisFactory when looking for redundant conditions used in assertions #2887)
  • Revert again commons-text from 1.11.0 to 1.10.0 to resolve a version conflict (#2686)
  • Fixed false positive MC_OVERRIDABLE_METHOD_CALL_IN_CONSTRUCTOR when referencing but not calling an overridable method #2837)
  • Update the filter XSD namespace and location for the upcoming 4.8.4 release #2909)

Added

  • New detector MultipleInstantiationsOfSingletons and introduced new bug types:
    • SING_SINGLETON_HAS_NONPRIVATE_CONSTRUCTOR is reported in case of a non-private constructor,
    • SING_SINGLETON_IMPLEMENTS_CLONEABLE is reported in case of a class directly implementing the Cloneable interface,
    • SING_SINGLETON_INDIRECTLY_IMPLEMENTS_CLONEABLE is reported when a class indirectly implements the Cloneable interface,
    • SING_SINGLETON_IMPLEMENTS_CLONE_METHOD is reported when a class does not implement the Cloneable interface, but has a clone() method,
    • SING_SINGLETON_IMPLEMENTS_SERIALIZABLE is reported when a class directly or indirectly implements the Serializable interface and
    • SING_SINGLETON_GETTER_NOT_SYNCHRONIZED is reported when the instance-getter method of the singleton class is not synchronized. (See SEI CERT MSC07-J)
  • Extend FindOverridableMethodCall detector with new bug type: MC_OVERRIDABLE_METHOD_CALL_IN_READ_OBJECT. It's reported when an overridable method is called from readObject(), according to SEI CERT rule SER09-J. Do not invoke overridable methods from the readObject() method.

Changed

  • Minor cleanup in connection with slashed and dotted names (#2805)

Build

  • Fix sonar coverage for project (#2796)
  • Upgraded the build to compile bug samples using Java 21 language features (#2813)
  • Add 'configurations.checkstyle resolution starategy' to control bug in gradle on exclusions not being excluded properly as seen in checkstyle usage. See checkstyle/checkstyle#14211 for more information. (#2798)
  • Allow our builds to work with jdk 11 with drop back on Eclipse to 4.24 and spring to 5.3.31. (#2604)
Commits
  • a86cfd3 release v4.8.4
  • 2240767 fix: Update the filter XSD namespace and location for the upcoming 4.8.4 (#2915)
  • 1bd7c25 chore(deps): update plugin io.github.gradle-nexus.publish-plugin to v2 (#2920)
  • 789d397 Keep track of constructed BugReporters for TextUiCommandLine (#2047) (#2894)
  • 3dff769 chore(deps): update plugin com.gradle.enterprise to v3.17 (#2917)
  • 3ca5182 fix(deps): update dependency jacoco to v0.8.12 (#2918)
  • 133a6f0 fix(deps): update dependency checkstyle to v10.15.0 (#2916)
  • 6d43261 Extend the FindOverridableMethodCall detector to handle SER09-J (#2895)
  • 9c36fdc Fix for false positive MC_OVERRIDABLE_METHOD_CALL_IN_CONSTRUCTOR when referen...
  • 0969918 chore(deps): update plugin org.sonarqube to v5 (#2914)
  • Additional commits viewable in compare view

Dependabot compatibility score

Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting @dependabot rebase.


Dependabot commands and options

You can trigger Dependabot actions by commenting on this PR:

  • @dependabot rebase will rebase this PR
  • @dependabot recreate will recreate this PR, overwriting any edits that have been made to it
  • @dependabot merge will merge this PR after your CI passes on it
  • @dependabot squash and merge will squash and merge this PR after your CI passes on it
  • @dependabot cancel merge will cancel a previously requested merge and block automerging
  • @dependabot reopen will reopen this PR if it is closed
  • @dependabot close will close this PR and stop Dependabot recreating it. You can achieve the same result by closing it manually
  • @dependabot show <dependency name> ignore conditions will show all of the ignore conditions of the specified dependency
  • @dependabot ignore this major version will close this PR and stop Dependabot creating any more for this major version (unless you reopen the PR or upgrade to it yourself)
  • @dependabot ignore this minor version will close this PR and stop Dependabot creating any more for this minor version (unless you reopen the PR or upgrade to it yourself)
  • @dependabot ignore this dependency will close this PR and stop Dependabot creating any more for this dependency (unless you reopen the PR or upgrade to it yourself)

@dependabot dependabot bot added dependencies Pull requests that update a dependency file java Pull requests that update Java code labels Apr 8, 2024
@github-actions github-actions bot enabled auto-merge April 8, 2024 07:14
Copy link
Contributor

@github-actions github-actions bot left a comment

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

I'm approving this pull request because it includes a patch or minor update

@dependabot dependabot bot force-pushed the dependabot/maven/com.github.spotbugs-spotbugs-annotations-4.8.4 branch from c427a63 to 4d64ad5 Compare April 8, 2024 07:16
Copy link
Contributor

@github-actions github-actions bot left a comment

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

I'm approving this pull request because it includes a patch or minor update

@dependabot dependabot bot force-pushed the dependabot/maven/com.github.spotbugs-spotbugs-annotations-4.8.4 branch from 4d64ad5 to a8a74a2 Compare April 8, 2024 07:22
Copy link
Contributor

@github-actions github-actions bot left a comment

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

I'm approving this pull request because it includes a patch or minor update

@dependabot dependabot bot force-pushed the dependabot/maven/com.github.spotbugs-spotbugs-annotations-4.8.4 branch from a8a74a2 to 46b80b5 Compare April 8, 2024 07:28
Copy link
Contributor

@github-actions github-actions bot left a comment

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

I'm approving this pull request because it includes a patch or minor update

Bumps [com.github.spotbugs:spotbugs-annotations](https://github.com/spotbugs/spotbugs) from 4.8.3 to 4.8.4.
- [Release notes](https://github.com/spotbugs/spotbugs/releases)
- [Changelog](https://github.com/spotbugs/spotbugs/blob/master/CHANGELOG.md)
- [Commits](spotbugs/spotbugs@4.8.3...4.8.4)

---
updated-dependencies:
- dependency-name: com.github.spotbugs:spotbugs-annotations
  dependency-type: direct:production
  update-type: version-update:semver-patch
...

Signed-off-by: dependabot[bot] <[email protected]>
@dependabot dependabot bot force-pushed the dependabot/maven/com.github.spotbugs-spotbugs-annotations-4.8.4 branch from 46b80b5 to e253897 Compare April 8, 2024 07:33
Copy link
Contributor

@github-actions github-actions bot left a comment

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

I'm approving this pull request because it includes a patch or minor update

@github-actions github-actions bot merged commit c10bca7 into master Apr 8, 2024
7 of 8 checks passed
@dependabot dependabot bot deleted the dependabot/maven/com.github.spotbugs-spotbugs-annotations-4.8.4 branch April 8, 2024 07:38
github-actions bot pushed a commit that referenced this pull request Apr 16, 2024
  - build(deps): bump slf4j-log4j.version from 2.0.7 to 2.0.13 (#1910)
  - build(deps): bump slf4j-log4j.version from 2.0.7 to 2.0.13
  - build(deps): bump software.amazon.jsii:jsii-runtime from 1.96.0 to 1.97.0 (#1914)
  - build(deps): bump software.amazon.jsii:jsii-runtime
  - build(deps): bump software.amazon.awssdk:bom from 2.25.26 to 2.25.31 (#1912)
  - build(deps): bump software.amazon.awssdk:bom from 2.25.26 to 2.25.31
  - build(deps): bump org.apache.maven.plugins:maven-gpg-plugin from 3.2.2 to 3.2.3 (#1913)
  - build(deps): bump org.apache.maven.plugins:maven-gpg-plugin
  - build(deps): bump org.elasticsearch.client:elasticsearch-rest-client from 8.13.1 to 8.13.2 (#1916)
  - build(deps): bump org.elasticsearch.client:elasticsearch-rest-client
  - build(deps): bump com.sap.cloud.db.jdbc:ngdbc from 2.20.11 to 2.20.17 (#1915)
  - build(deps): bump com.sap.cloud.db.jdbc:ngdbc from 2.20.11 to 2.20.17
  - build(deps): bump org.testng:testng from 7.10.0 to 7.10.1 (#1911)
  - build(deps): bump org.testng:testng from 7.10.0 to 7.10.1
  - build(deps): bump org.apache.maven.plugins:maven-jar-plugin from 3.3.0 to 3.4.0 (#1909)
  - build(deps): bump org.apache.maven.plugins:maven-jar-plugin
  - build(deps): bump aws-sdk.version from 1.12.696 to 1.12.701 (#1908)
  - build(deps): bump aws-sdk.version from 1.12.696 to 1.12.701
  - Qpt vertica changes (#1853)
  - Query passthrough changes for Cloudwatch connector (#1906)
  - Extended QPT to athena-neptune for property graph (#1886)
  - Extended QPT to athena-hbase (#1876)
  - build(deps): bump org.apache.maven.plugins:maven-source-plugin from 3.3.0 to 3.3.1 (#1897)
  - build(deps): bump org.apache.maven.plugins:maven-source-plugin
  - build(deps): bump software.amazon.awssdk:bom from 2.25.21 to 2.25.26 (#1893)
  - build(deps): bump software.amazon.awssdk:bom from 2.25.21 to 2.25.26
  - build(deps): bump com.microsoft.sqlserver:mssql-jdbc from 12.6.1.jre11 to 12.7.0.jre11-preview (#1900)
  - build(deps): bump com.microsoft.sqlserver:mssql-jdbc
  - build(deps): bump io.grpc:grpc-api from 1.62.2 to 1.63.0 (#1891)
  - build(deps): bump io.grpc:grpc-api from 1.62.2 to 1.63.0
  - build(deps): bump org.elasticsearch.client:elasticsearch-rest-client from 8.13.0 to 8.13.1 (#1896)
  - build(deps): bump org.elasticsearch.client:elasticsearch-rest-client
  - build(deps): bump org.jacoco:jacoco-maven-plugin from 0.8.11 to 0.8.12 (#1899)
  - build(deps): bump org.jacoco:jacoco-maven-plugin from 0.8.11 to 0.8.12
  - build(deps): bump net.snowflake:snowflake-jdbc from 3.15.0 to 3.15.1 (#1898)
  - build(deps): bump net.snowflake:snowflake-jdbc from 3.15.0 to 3.15.1
  - build(deps): bump com.github.spotbugs:spotbugs-annotations from 4.8.3 to 4.8.4 (#1901)
  - build(deps): bump com.github.spotbugs:spotbugs-annotations
  - build(deps-dev): bump nl.jqno.equalsverifier:equalsverifier from 3.16 to 3.16.1 (#1894)
  - build(deps-dev): bump nl.jqno.equalsverifier:equalsverifier
  - build(deps): bump com.google.cloud:google-cloud-resourcemanager from 1.41.0 to 1.43.0 (#1892)
  - build(deps): bump com.google.cloud:google-cloud-resourcemanager
  - build(deps): bump software.amazon.msk:aws-msk-iam-auth from 2.0.3 to 2.1.0 (#1895)
  - build(deps): bump software.amazon.msk:aws-msk-iam-auth
  - build(deps): bump aws-sdk.version from 1.12.691 to 1.12.696 (#1890)
  - build(deps): bump aws-sdk.version from 1.12.691 to 1.12.696
  - build(deps): bump org.testng:testng from 7.9.0 to 7.10.0 (#1889)
  - build(deps): bump org.testng:testng from 7.9.0 to 7.10.0
  - build(deps): bump org.elasticsearch.client:elasticsearch-rest-client from 8.12.2 to 8.13.0 (#1882)
  - build(deps): bump org.elasticsearch.client:elasticsearch-rest-client
  - build(deps): bump com.google.cloud:google-cloud-resourcemanager from 1.40.0 to 1.41.0 (#1883)
  - build(deps): bump com.google.cloud:google-cloud-resourcemanager
  - build(deps): bump com.microsoft.azure:msal4j from 1.14.3 to 1.15.0 (#1880)
  - build(deps): bump com.microsoft.azure:msal4j from 1.14.3 to 1.15.0
  - build(deps): bump software.amazon.awssdk:bom from 2.25.17 to 2.25.21 (#1879)
  - build(deps): bump software.amazon.awssdk:bom from 2.25.17 to 2.25.21
  - build(deps): bump aws-sdk.version from 1.12.686 to 1.12.691 (#1878)
  - build(deps): bump aws-sdk.version from 1.12.686 to 1.12.691
  - qpt change for elastic search (#1854)
  - Extended QPT to athena-sqlserver (#1823)
  - build(deps): bump software.amazon.jsii:jsii-runtime from 1.95.0 to 1.96.0 (#1869)
  - build(deps): bump software.amazon.jsii:jsii-runtime
  - build(deps): bump org.apache.maven.plugins:maven-compiler-plugin from 3.12.1 to 3.13.0 (#1867)
  - build(deps): bump org.apache.maven.plugins:maven-compiler-plugin
  - build(deps): bump software.amazon.awssdk:bom from 2.25.11 to 2.25.17 (#1874)
  - build(deps): bump software.amazon.awssdk:bom from 2.25.11 to 2.25.17
  - build(deps): bump org.apache.maven.plugins:maven-assembly-plugin from 3.7.0 to 3.7.1 (#1870)
  - build(deps): bump org.apache.maven.plugins:maven-assembly-plugin
  - build(deps-dev): bump nl.jqno.equalsverifier:equalsverifier from 3.15.8 to 3.16 (#1866)
  - build(deps-dev): bump nl.jqno.equalsverifier:equalsverifier
  - build(deps): bump org.apache.maven.plugins:maven-gpg-plugin from 3.2.0 to 3.2.2 (#1875)
  - build(deps): bump org.apache.maven.plugins:maven-gpg-plugin
  - build(deps): bump com.sap.cloud.db.jdbc:ngdbc from 2.19.16 to 2.20.11 (#1864)
  - build(deps): bump com.sap.cloud.db.jdbc:ngdbc from 2.19.16 to 2.20.11
  - build(deps): bump org.apache.hadoop:hadoop-common from 3.3.6 to 3.4.0 (#1871)
  - build(deps): bump org.apache.hadoop:hadoop-common from 3.3.6 to 3.4.0
  - build(deps): bump com.google.cloud:google-cloud-storage from 2.36.0 to 2.36.1 (#1863)
  - build(deps): bump com.google.cloud:google-cloud-storage
  - build(deps): bump aws-sdk.version from 1.12.681 to 1.12.686 (#1862)
  - build(deps): bump aws-sdk.version from 1.12.681 to 1.12.686
  - build(deps): bump dependabot/fetch-metadata from 1 to 2 (#1873)
  - build(deps): bump dependabot/fetch-metadata from 1 to 2
  - Extended QPT to athena-Synapse (#1831)
  - Extended QPT To Datalakegen2 (#1822)
  - Extended QPT to athena-db2 (#1825)
  - Extended QPT to athena-oracle (#1827)
  - Extended QPT to athena-Saphana (#1828)
  - Extended QPT to athena-teradata (#1830)
  - Extended QPT to athena-hortonworks-hive (#1824)
  - Extended QPT to athena-cloudera-hive (#1826)
  - Extended QPT to athena-snowflake (#1829)
  - Extended QPT to athena-Impala (#1832)
  - Extended QPT to athena-db2-as400 (#1833)
  - Extended QPT to athena-timestream (#1857)
  - build(deps): bump com.google.cloud:google-cloud-resourcemanager from 1.39.0 to 1.40.0 (#1861)
  - build(deps): bump com.google.cloud:google-cloud-resourcemanager
  - Extended QPT to athena-dynamodb (#1819)
  - SPILL_QUEUE_CAPACITY config property can now be set as all lowercase (#1852)
  - Extend QPT to Postgresql & Redshift (#1820)
  - build(deps): bump org.apache.commons:commons-configuration2 from 2.10.0 to 2.10.1 in /athena-neptune (#1855)
  - build(deps): bump org.apache.commons:commons-configuration2
  - Feature: Enable/Disable kerberos authentication for cloudera manager hbase instance (#1793)
  - build(deps): bump io.grpc:grpc-api from 1.61.0 to 1.62.2 (#1844)
  - build(deps): bump io.grpc:grpc-api from 1.61.0 to 1.62.2
  - build(deps): bump org.apache.maven.plugins:maven-gpg-plugin from 3.1.0 to 3.2.0 (#1843)
  - build(deps): bump org.apache.maven.plugins:maven-gpg-plugin
  - build(deps): bump com.google.cloud:google-cloud-storage from 2.35.0 to 2.36.0 (#1846)
  - build(deps): bump com.google.cloud:google-cloud-storage
  - build(deps): bump net.jqwik:jqwik from 1.8.3 to 1.8.4 (#1841)
  - build(deps): bump net.jqwik:jqwik from 1.8.3 to 1.8.4
  - build(deps): bump org.apache.commons:commons-configuration2 from 2.9.0 to 2.10.0 (#1845)
  - build(deps): bump org.apache.commons:commons-configuration2
  - build(deps): bump org.postgresql:postgresql from 42.7.2 to 42.7.3 (#1847)
  - build(deps): bump org.postgresql:postgresql from 42.7.2 to 42.7.3
  - build(deps): bump fasterxml.jackson.version from 2.16.2 to 2.17.0 (#1837)
  - build(deps): bump fasterxml.jackson.version from 2.16.2 to 2.17.0
  - build(deps): bump io.lettuce:lettuce-core from 6.3.1.RELEASE to 6.3.2.RELEASE (#1839)
  - build(deps): bump io.lettuce:lettuce-core
  - build(deps): bump software.amazon.awssdk:bom from 2.25.4 to 2.25.11 (#1842)
  - build(deps): bump software.amazon.awssdk:bom from 2.25.4 to 2.25.11
  - build(deps): bump hbase.version from 2.5.7-hadoop3 to 2.5.8-hadoop3 (#1838)
  - build(deps): bump hbase.version from 2.5.7-hadoop3 to 2.5.8-hadoop3
  - build(deps): bump aws-sdk.version from 1.12.676 to 1.12.681 (#1835)
  - build(deps): bump aws-sdk.version from 1.12.676 to 1.12.681
  - build(deps): bump com.google.guava:guava from 33.0.0-jre to 33.1.0-jre (#1836)
  - build(deps): bump com.google.guava:guava from 33.0.0-jre to 33.1.0-jre
  - build(deps): bump org.apache.zookeeper:zookeeper from 3.9.1 to 3.9.2 in /athena-hbase (#1834)
  - build(deps): bump org.apache.zookeeper:zookeeper in /athena-hbase
  - Migrate DynamoDB Connector to use AWS SDK V2 (#1810)
  - BUG 1728 : pom changes for bigquery connector (#1788)
  - Extended QPT to athena-docdb (#1796)
  - Extended QPT to athena-bigquery (#1795)
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
dependencies Pull requests that update a dependency file java Pull requests that update Java code
Projects
None yet
Development

Successfully merging this pull request may close these issues.

0 participants