Skip to content

chore(deps): bump the backend-dependencies group across 1 directory with 6 updates - #820

Open
dependabot[bot] wants to merge 1 commit into
mainfrom
dependabot/gradle/backend/backend-dependencies-d42eb94bc7
Open

dependabot[bot] wants to merge 1 commit into
mainfrom
dependabot/gradle/backend/backend-dependencies-d42eb94bc7

Conversation

@dependabot

@dependabot dependabot Bot commented on behalf of github Sep 29, 2026

Copy link
Copy Markdown
Contributor

Bumps the backend-dependencies group with 6 updates in the /backend directory:

Package From To
org.springdoc:springdoc-openapi-starter-webmvc-ui 2.9.0 2.9.1
com.github.ben-manes.caffeine:caffeine 3.2.4 3.3.0
com.fasterxml.jackson.core:jackson-databind 2.22.2 2.22.3
com.google.protobuf:protobuf-java 4.36.1 4.36.2
com.google.protobuf:protobuf-java-util 4.36.1 4.36.2
com.google.protobuf:protobuf-java-util 4.36.1 4.36.2
com.google.protobuf:protoc 4.36.1 4.36.2

Updates org.springdoc:springdoc-openapi-starter-webmvc-ui from 2.9.0 to 2.9.1

Release notes

Sourced from org.springdoc:springdoc-openapi-starter-webmvc-ui's releases.

springdoc-openapi v2.9.1 released!

Security

  • GHSA-rhhx-6j8h-8cvw – Unbounded per-locale OpenAPI cache allows memory exhaustion via Accept-Language
  • GHSA-c925-vm88-mpp9 – Scalar starters trust client-supplied forwarded headers and render from a shared mutable bean
  • CVE-2026-75838 – Cross-site scripting in the DOMPurify bundled with swagger-ui, addressed by upgrading swagger-ui to 5.32.14

Added

  • #3340 – Describe JsonNullable values without their Java wrapper
  • #3325 – Manage the swagger artifacts in springdoc-openapi-bom, so that modules holding only the annotations stay in lockstep
  • #3321 – Add springdoc.login-endpoint.username-example and springdoc.login-endpoint.password-example to document the Spring Security login endpoint

Changed

  • The Scalar starters no longer register forwarded-header handling. Set server.forward-headers-strategy=framework (or native) behind a trusted proxy
  • Add springdoc.cache.max-entries (default 100) to bound the per-locale OpenAPI cache
  • Document the security policy and the release versioning scheme
  • #3351 – java.time.Duration, LocalTime and OffsetTime are now resolved by swagger-core instead of being forced to a bare string, so they carry a format (duration and partial-time respectively for the first two)
  • A property whose type only implements Set indirectly (LinkedHashSet, TreeSet, …) is now described with uniqueItems: true, following swagger-api/swagger-core#5265
  • Upgrade swagger-core to version 2.2.55
  • Upgrade swagger-ui to version 5.32.14

Fixed

  • #3320 – @Order and Ordered ignored when applying customizers
  • #3319 – A Page nested in another schema is not replaced by PagedModel
  • #3313 – Springdoc auto-configurations rely on unspecified auto-configuration ordering
  • #3331 – Validation annotations declared inside Optional parameters are dropped
  • #3322 – Validation annotations on a container's type argument leak between parameters
  • #3315 – An OAS 3.1 JsonSchema cannot be cloned through JSON
  • #3314 – Json Processing Exception occurred is logged for every constrained parameter whose schema is not a JsonSchema
  • #3300 – TYPE_USE annotations on @ParameterObject fields are not passed along
  • #3341 – Stabilize Spring Data Sort and Pageable schema property order
  • #3338 – Kotlin nullability interpretation of the Any? type
  • #3332 – The properties a Kotlin entity inherits from an @Embeddable are missing from the Spring Data REST schemas
  • #3136 – A Spring Data REST association to a non-exported entity expands its @EmbeddedId and @MapsId fields recursively in the response schemas
  • The Spring Data REST response post-processing rewrote an association property in place, so the …Response refs could leak into the schema shared with the request body representation
  • #3317 – Ignore an injected HttpHeaders parameter explicitly. The reported failure needs Spring Framework 7, where HttpHeaders stopped implementing MultiValueMap; on this line it is still covered by the Map entry of the ignore list, so this is regression cover rather than a behaviour change
  • Harden the Spring Data REST response post-processing against an _embedded schema that carries no properties

New Contributors

Full Changelog: springdoc/springdoc-openapi@v2.9.0...v2.9.1

Changelog

Sourced from org.springdoc:springdoc-openapi-starter-webmvc-ui's changelog.

[2.9.1] - 2026-09-06

Security

  • GHSA-rhhx-6j8h-8cvw – Unbounded per-locale OpenAPI cache allows memory exhaustion via Accept-Language
  • GHSA-c925-vm88-mpp9 – Scalar starters trust client-supplied forwarded headers and render from a shared mutable bean
  • CVE-2026-75838 – Cross-site scripting in the DOMPurify bundled with swagger-ui, addressed by upgrading swagger-ui to 5.32.14

Added

  • #3340 – Describe JsonNullable values without their Java wrapper
  • #3325 – Manage the swagger artifacts in springdoc-openapi-bom, so that modules holding only the annotations stay in lockstep
  • #3321 – Add springdoc.login-endpoint.username-example and springdoc.login-endpoint.password-example to document the Spring Security login endpoint

Changed

  • The Scalar starters no longer register forwarded-header handling. Set server.forward-headers-strategy=framework (or native) behind a trusted proxy
  • Add springdoc.cache.max-entries (default 100) to bound the per-locale OpenAPI cache
  • Document the security policy and the release versioning scheme
  • #3351 – java.time.Duration, LocalTime and OffsetTime are now resolved by swagger-core instead of being forced to a bare string, so they carry a format (duration and partial-time respectively for the first two)
  • A property whose type only implements Set indirectly (LinkedHashSet, TreeSet, …) is now described with uniqueItems: true, following swagger-api/swagger-core#5265
  • Upgrade swagger-core to version 2.2.55
  • Upgrade swagger-ui to version 5.32.14

Fixed

  • #3320 – @Order and Ordered ignored when applying customizers
  • #3319 – A Page nested in another schema is not replaced by PagedModel
  • #3313 – Springdoc auto-configurations rely on unspecified auto-configuration ordering
  • #3331 – Validation annotations declared inside Optional parameters are dropped
  • #3322 – Validation annotations on a container's type argument leak between parameters
  • #3315 – An OAS 3.1 JsonSchema cannot be cloned through JSON
  • #3314 – Json Processing Exception occurred is logged for every constrained parameter whose schema is not a JsonSchema
  • #3300 – TYPE_USE annotations on @ParameterObject fields are not passed along
  • #3341 – Stabilize Spring Data Sort and Pageable schema property order
  • #3338 – Kotlin nullability interpretation of the Any? type
  • #3332 – The properties a Kotlin entity inherits from an @Embeddable are missing from the Spring Data REST schemas
  • #3136 – A Spring Data REST association to a non-exported entity expands its @EmbeddedId and @MapsId fields recursively in the response schemas
  • The Spring Data REST response post-processing rewrote an association property in place, so the …Response refs could leak into the schema shared with the request body representation
  • #3317 – Ignore an injected HttpHeaders parameter explicitly. The reported failure needs Spring Framework 7, where HttpHeaders stopped implementing MultiValueMap; on this line it is still covered by the Map entry of the ignore list, so this is regression cover rather than a behaviour change
  • Harden the Spring Data REST response post-processing against an _embedded schema that carries no properties
Commits
  • 1c53464 [maven-release-plugin] prepare release v2.9.1
  • 94190e9 ci: give the 2.x branch its own release workflow
  • bfd5703 docs: record the swagger-ui 5.32.14 upgrade as a security fix for 2.9.1
  • 473785c Merge swagger-core 2.2.55 upgrade
  • 39968b3 Upgrade swagger-core to 2.2.55
  • 2e7d271 Merge backport of #3351 - swagger-core 2.2.54
  • c772cdc Record the swagger-core 2.2.54 upgrade in the changelog
  • a15cb5a upgrade swagger-core from 2.2.53 to 2.2.54
  • f05b1fc Merge backport of #3323/#3321, #3317 and the Spring Data REST response fixes
  • 38acf19 Record the backported fixes in the changelog
  • Additional commits viewable in compare view

Updates com.github.ben-manes.caffeine:caffeine from 3.2.4 to 3.3.0

Release notes

Sourced from com.github.ben-manes.caffeine:caffeine's releases.

3.3.0

  • Improved read performance by avoiding false sharing in the fast-path check
  • Improved adaptive climber for small caches and shifting workloads
  • Fixed various minor issues found using AI audits
  • Fixed over-aggressive refresh discard (#1970)
Commits
  • af86011 fix jcache audit triage
  • f063e56 Prevent overflow in snapshot durations
  • 5b6fbd9 Saturate the audit stillness counter
  • 48cb408 Read lazy cache views and policies once
  • 4978d18 Normalize JCache processor loader failures
  • c9038d8 Consume JCache iterator removals before listener failures
  • 0b0afd2 polish
  • c0edd00 restore coverage lost to recent fixes
  • 5283c96 make CLOCK-Pro's cold hand a setting
  • d15c205 make the bulk cache loaders serializable
  • Additional commits viewable in compare view

Updates com.fasterxml.jackson.core:jackson-databind from 2.22.2 to 2.22.3

Commits
  • 4385c5f [maven-release-plugin] prepare release jackson-databind-2.22.3
  • ccb4fd0 Prep for 2.22.3 release
  • 2958412 Merge branch '2.21' into 2.22
  • 1215b94 Post-release dep version bump
  • 1f0df62 [maven-release-plugin] prepare for next development iteration
  • 13a9ff4 [maven-release-plugin] prepare release jackson-databind-2.21.7
  • d168f96 Prep for 2.21.7 release
  • eaf5c76 Merge branch '2.21' into 2.22
  • e05ef4c Merge branch '2.20' into 2.21
  • f6d4000 Merge branch '2.19' into 2.20
  • Additional commits viewable in compare view

Updates com.google.protobuf:protobuf-java from 4.36.1 to 4.36.2

Commits

Updates com.google.protobuf:protobuf-java-util from 4.36.1 to 4.36.2

Updates com.google.protobuf:protobuf-java-util from 4.36.1 to 4.36.2

Updates com.google.protobuf:protoc from 4.36.1 to 4.36.2

Commits

Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting @dependabot rebase.


Dependabot commands and options

You can trigger Dependabot actions by commenting on this PR:

  • @dependabot rebase will rebase this PR
  • @dependabot recreate will recreate this PR, overwriting any edits that have been made to it
  • @dependabot show <dependency name> ignore conditions will show all of the ignore conditions of the specified dependency
  • @dependabot ignore <dependency name> major version will close this group update PR and stop Dependabot creating any more for the specific dependency's major version (unless you unignore this specific dependency's major version or upgrade to it yourself)
  • @dependabot ignore <dependency name> minor version will close this group update PR and stop Dependabot creating any more for the specific dependency's minor version (unless you unignore this specific dependency's minor version or upgrade to it yourself)
  • @dependabot ignore <dependency name> will close this group update PR and stop Dependabot creating any more for the specific dependency (unless you unignore this specific dependency or upgrade to it yourself)
  • @dependabot unignore <dependency name> will remove all of the ignore conditions of the specified dependency
  • @dependabot unignore <dependency name> <ignore condition> will remove the ignore condition of the specified dependency and ignore conditions

…ith 6 updates

Bumps the backend-dependencies group with 6 updates in the /backend directory:

| Package | From | To |
| --- | --- | --- |
| [org.springdoc:springdoc-openapi-starter-webmvc-ui](https://github.com/springdoc/springdoc-openapi) | `2.9.0` | `2.9.1` |
| [com.github.ben-manes.caffeine:caffeine](https://github.com/ben-manes/caffeine) | `3.2.4` | `3.3.0` |
| [com.fasterxml.jackson.core:jackson-databind](https://github.com/FasterXML/jackson-databind) | `2.22.2` | `2.22.3` |
| [com.google.protobuf:protobuf-java](https://github.com/protocolbuffers/protobuf) | `4.36.1` | `4.36.2` |
| com.google.protobuf:protobuf-java-util | `4.36.1` | `4.36.2` |
| com.google.protobuf:protobuf-java-util | `4.36.1` | `4.36.2` |
| [com.google.protobuf:protoc](https://github.com/protocolbuffers/protobuf) | `4.36.1` | `4.36.2` |



Updates `org.springdoc:springdoc-openapi-starter-webmvc-ui` from 2.9.0 to 2.9.1
- [Release notes](https://github.com/springdoc/springdoc-openapi/releases)
- [Changelog](https://github.com/springdoc/springdoc-openapi/blob/v2.9.1/CHANGELOG.md)
- [Commits](springdoc/springdoc-openapi@v2.9.0...v2.9.1)

Updates `com.github.ben-manes.caffeine:caffeine` from 3.2.4 to 3.3.0
- [Release notes](https://github.com/ben-manes/caffeine/releases)
- [Commits](ben-manes/caffeine@v3.2.4...v3.3.0)

Updates `com.fasterxml.jackson.core:jackson-databind` from 2.22.2 to 2.22.3
- [Commits](FasterXML/jackson-databind@jackson-databind-2.22.2...jackson-databind-2.22.3)

Updates `com.google.protobuf:protobuf-java` from 4.36.1 to 4.36.2
- [Release notes](https://github.com/protocolbuffers/protobuf/releases)
- [Commits](https://github.com/protocolbuffers/protobuf/commits)

Updates `com.google.protobuf:protobuf-java-util` from 4.36.1 to 4.36.2

Updates `com.google.protobuf:protobuf-java-util` from 4.36.1 to 4.36.2

Updates `com.google.protobuf:protoc` from 4.36.1 to 4.36.2
- [Release notes](https://github.com/protocolbuffers/protobuf/releases)
- [Commits](https://github.com/protocolbuffers/protobuf/commits)

---
updated-dependencies:
- dependency-name: org.springdoc:springdoc-openapi-starter-webmvc-ui
  dependency-version: 2.9.1
  dependency-type: direct:production
  update-type: version-update:semver-patch
  dependency-group: backend-dependencies
- dependency-name: com.github.ben-manes.caffeine:caffeine
  dependency-version: 3.3.0
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: backend-dependencies
- dependency-name: com.fasterxml.jackson.core:jackson-databind
  dependency-version: 2.22.3
  dependency-type: direct:production
  update-type: version-update:semver-patch
  dependency-group: backend-dependencies
- dependency-name: com.google.protobuf:protobuf-java
  dependency-version: 4.36.2
  dependency-type: direct:production
  update-type: version-update:semver-patch
  dependency-group: backend-dependencies
- dependency-name: com.google.protobuf:protobuf-java-util
  dependency-version: 4.36.2
  dependency-type: direct:production
  update-type: version-update:semver-patch
  dependency-group: backend-dependencies
- dependency-name: com.google.protobuf:protobuf-java-util
  dependency-version: 4.36.2
  dependency-type: direct:production
  update-type: version-update:semver-patch
  dependency-group: backend-dependencies
- dependency-name: com.google.protobuf:protoc
  dependency-version: 4.36.2
  dependency-type: direct:production
  update-type: version-update:semver-patch
  dependency-group: backend-dependencies
...

Signed-off-by: dependabot[bot] <support@github.com>
@dependabot dependabot Bot added dependencies Pull requests that update a dependency file java Pull requests that update java code labels Sep 29, 2026
@coderabbitai

coderabbitai Bot commented Sep 29, 2026

Copy link
Copy Markdown

Important

Review skipped

Bot user detected.

To trigger a single review, invoke the @coderabbitai review command.

⚙️ Run configuration

Configuration used: Repository: Shadowfit/init/.coderabbit.yaml

Review profile: CHILL

Plan: Advanced

Run ID: f1ebfff9-1d2a-4596-a6a4-e421202fd43e

You can disable this status message by setting the reviews.review_status to false in the CodeRabbit configuration file.

Use the checkbox below for a quick retry:

  • 🔍 Trigger review

Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out.

❤️ Share

Comment @coderabbitai help to get the list of available commands.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

dependencies Pull requests that update a dependency file java Pull requests that update java code

Projects

None yet

Development

Successfully merging this pull request may close these issues.

0 participants