Skip to content

Bump the prod-deps group with 6 updates - #789

Merged
thmarx merged 1 commit into
mainfrom
dependabot/maven/prod-deps-bb1964247c
Sep 30, 2026
Merged

thmarx merged 1 commit into
mainfrom
dependabot/maven/prod-deps-bb1964247c

Conversation

@dependabot

@dependabot dependabot Bot commented on behalf of github Sep 30, 2026

Copy link
Copy Markdown
Contributor

Bumps the prod-deps group with 6 updates:

Package From To
org.tomlj:tomlj 2.0.1 2.1.1
com.h2database:h2-mvstore 2.5.250 2.5.252
org.apache.commons:commons-lang3 3.20.0 3.21.0
org.apache.tika:tika-core 4.0.0 4.1.0
io.github.wasabithumb:jtoml 1.8.0 1.8.1
io.github.wasabithumb:jtoml-serializer-gson 1.8.0 1.8.1

Updates org.tomlj:tomlj from 2.0.1 to 2.1.1

Release notes

Sourced from org.tomlj:tomlj's releases.

Release 2.1.1

TomlJ is a parser and serializer for Tom's Obvious, Minimal Language (TOML).

2.1.1 is a bug-fix release.

Changes since last release

  • Binding no longer keeps TomlJ's class loader from being unloaded, so an application that bundles TomlJ can be unloaded on redeploy.
  • Fixes in binding: a float too small to hold a value is reported as out of range, a sorted set of a type that is not Comparable gives a clear error, and a GenericType subclass of another generic class names the right type.
  • Errors when writing objects now say "Cannot write", and name a JDK class correctly.
  • Fixes in writing edited documents, where a copied table or a comment could be written so that it read back differently.

Getting TomlJ

TomlJ is published to Maven Central.

To include using Gradle, add the following to your dependencies:

implementation 'org.tomlj:tomlj:2.1.1'

To include using Maven:

<dependency>
  <groupId>org.tomlj</groupId>
  <artifactId>tomlj</artifactId>
  <version>2.1.1</version>
</dependency>

If your project already uses ANTLR and you would rather share one copy of the runtime, use org.tomlj:tomlj-antlr:2.1.1 instead.

You may also download the jars directly and include them in your project.

Usage and Documentation

For basic usage, please see the README. The examples directory has twelve small programs using TomlJ, from reading a file and reporting its errors to editing and writing documents, reading their comments, and binding them to records. Complete documentation, in Javadoc, is available here: http://tomlj.org/docs/java/2.1.1/

Signature

All artifacts and release tags are signed by Chris Leishman, using key id 0xB5A9E81B565E89E0.

Release 2.1.0

TomlJ is a parser and serializer for Tom's Obvious, Minimal Language (TOML).

2.1.0 adds binding between TOML documents and Java objects, in both directions, and three options for the default writing style.

Changes since last release

Binding to Java objects

... (truncated)

Commits
  • 84f93d8 Merge pull request #147 from tomlj/release-2.1.1
  • c1e71f0 Update README for 2.1.1
  • 4c1f44a Increment version to 2.1.1
  • a922829 Merge pull request #146 from tomlj/fix-root-comment-order
  • 4073225 Remove a stray word in the writing guide
  • f4a77e1 Keep a new root comment after earlier sections
  • 88625cd Merge pull request #145 from tomlj/fix-write-access-error
  • 6464b73 Merge pull request #144 from tomlj/fix-generic-type-subclass
  • 88646f4 Merge pull request #143 from tomlj/fix-copied-key-text
  • dd549be Fix the errors for classes TomlJ cannot write
  • Additional commits viewable in compare view

Updates com.h2database:h2-mvstore from 2.5.250 to 2.5.252

Release notes

Sourced from com.h2database:h2-mvstore's releases.

Version 2.5.252

Commits
  • f986838 in preparation for a release
  • 06c34a7 Merge pull request #4418 from andreitokar/issues-4380-4376
  • 1aef3e0 #4376: Reading INFORMATION_SCHEMA.COLUMNS fails with a NPE while any material...
  • 4bb8aee #4380: creating a MATERIALIZED VIEW makes a persistent database permanently u...
  • 95b6af0 Merge pull request #4417 from andreitokar/issue-4395
  • 6ec30b6 #4395 disallow constraints between temporary and permanent tables
  • 0f0f856 Merge pull request #4416 from andreitokar/issue-4405
  • f718b76 #4405 SecureFileStore.readFully() may skip decryption
  • e231ff7 #4405 SecureFileStore.readFully() may skip
  • 4da0d1d Merge pull request #4415 from jjh75607/fix/log-sql-aarch64
  • Additional commits viewable in compare view

Updates org.apache.commons:commons-lang3 from 3.20.0 to 3.21.0

Updates org.apache.tika:tika-core from 4.0.0 to 4.1.0

Changelog

Sourced from org.apache.tika:tika-core's changelog.

Release 4.2.0 - unreleased

  • XmlSecurityContractTest pins XMLReaderUtils' XXE and entity-expansion defenses forbidden-apis now rejects building JAXP or Commons Secure XML parsers anywhere but XMLReaderUtils (TIKA-4939).

  • Retire Tika's entity expansion limit (default 20) in SAX, DOM and StAX parsing in favor of standard Java configuration methods (TIKA-4940).

  • Report the external DTDs and entities a document's XML referenced, which Tika never resolves: tk:xml-external-reference (up to 20 system ids) and tk:xml-external-reference-count on that document's metadata, and tk:xml-external-reference-embedded on a container whose embedded document had any. Every resolver Tika installs answers with an empty stream, never null (TIKA-4941).

  • Deprecate XMLReaderUtils.getXMLInputFactory() and use SAX for XFA (TIKA-4938).

Release 4.1.0 - 9/26/2026

HIGHLIGHTS

  • OCR and enrichment engines are selected by name in a new "text-recognizers" list ("[]" turns enrichment off; no list resolves one engine per media type at startup); the image and PDF parsers invoke them rather than the composite dispatching to them. The image/ocr-* pseudo-types are retired; a third-party engine still advertising them is a legacy text recognizer with a WARN. VLM parsers gain "textRecognizer" (TIKA-4872, TIKA-4884).

  • New "exception-reporting" parse-context config redacts and bounds exception text in metadata, tika-server error bodies and pipes/grpc messages; FileSystemEmitter writes atomically. Compat: tk:exception:* values may now begin with the TikaException wrapper line (TIKA-4848).

PERFORMANCE

  • Detection (magic ~35% faster on unmatched input, override keys honored before magic, cached type->parser map), markdown output ~30x faster, .doc cleanup, CSV sniffing, zip legacy-method rewinds, pipes ACK overlap, raw UTF-8 content passback for tika-server (content-bytes-config). Compat: with a Content-Type override set, DefaultDetector no longer lets a more specific magic result overrule it (TIKA-4868).

  • PDF incremental-update scanning reads in blocks; ~4x less CPU (TIKA-4898).

  • Embedded documents in Office files, PDFs, PST and the zip-family containers are re-opened from their container on rewind instead of cached (TIKA-4878).

  • Improve spooling/decrease number of spills to disk. The pipes cache

... (truncated)

Commits
  • e8dd07a [maven-release-plugin] prepare release 4.1.0-rc3
  • e53a7b4 TIKA-4836: update aws
  • 4df21a6 prep for rc3
  • e6bc8be TIKA-4933: build the .run-info test fixture at test time; the source release ...
  • f0b7ad7 [maven-release-plugin] prepare for next development iteration
  • 5a75213 [maven-release-plugin] prepare release 4.1.0-rc2
  • bb1f6f2 update CHANGES.txt
  • 5c1cda5 TIKA-4932: pipes no longer copies the caller's Content-Type hint back… (#3258)
  • ebc845c TIKA-4931: fix overrides in PipesForkParser (#3257)
  • 739a9c3 TIKA-4927: overwrite stale NER test models with the verified cache copy (#3256)
  • Additional commits viewable in compare view

Updates io.github.wasabithumb:jtoml from 1.8.0 to 1.8.1

Release notes

Sourced from io.github.wasabithumb:jtoml's releases.

1.8.1

Change notes:

  • Implement indexed TomlArray#add to insert elements at any position, not just the end (#93)
  • Some internal improvements to TomlKey (#94)
    • TomlKey now implements List<String> with/out RandomAccess, still immutable
    • Improved join & split behavior, reducing memory footprint
  • Migrate to JSpecify nullability annotations (#95)
  • Added some package-level documentation
Commits
  • 92c5ef9 Merge pull request #96 from WasabiThumb/staging
  • 4d1bfe6 [chore] bump version
  • 2ab206c Merge pull request #95 from WasabiThumb/feat/jspecify
  • c4824bd Use JSpecify annotations
  • 87ae8a0 Merge pull request #94 from WasabiThumb/feat/list-keys
  • 8525490 Merge pull request #93 from WasabiThumb/fix/toml-array-add-indexed
  • 85369d5 Remove effectively unused default subList implementation
  • b88f668 [doc] Improve language in TomlKey
  • 21c2c11 Add sequential iterator to SlicedTomlKey
  • 69e2c87 Fix slice regression
  • Additional commits viewable in compare view

Updates io.github.wasabithumb:jtoml-serializer-gson from 1.8.0 to 1.8.1

Release notes

Sourced from io.github.wasabithumb:jtoml-serializer-gson's releases.

1.8.1

Change notes:

  • Implement indexed TomlArray#add to insert elements at any position, not just the end (#93)
  • Some internal improvements to TomlKey (#94)
    • TomlKey now implements List<String> with/out RandomAccess, still immutable
    • Improved join & split behavior, reducing memory footprint
  • Migrate to JSpecify nullability annotations (#95)
  • Added some package-level documentation
Commits
  • 92c5ef9 Merge pull request #96 from WasabiThumb/staging
  • 4d1bfe6 [chore] bump version
  • 2ab206c Merge pull request #95 from WasabiThumb/feat/jspecify
  • c4824bd Use JSpecify annotations
  • 87ae8a0 Merge pull request #94 from WasabiThumb/feat/list-keys
  • 8525490 Merge pull request #93 from WasabiThumb/fix/toml-array-add-indexed
  • 85369d5 Remove effectively unused default subList implementation
  • b88f668 [doc] Improve language in TomlKey
  • 21c2c11 Add sequential iterator to SlicedTomlKey
  • 69e2c87 Fix slice regression
  • Additional commits viewable in compare view

Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting @dependabot rebase.


Dependabot commands and options

You can trigger Dependabot actions by commenting on this PR:

  • @dependabot rebase will rebase this PR
  • @dependabot recreate will recreate this PR, overwriting any edits that have been made to it
  • @dependabot show <dependency name> ignore conditions will show all of the ignore conditions of the specified dependency
  • @dependabot ignore <dependency name> major version will close this group update PR and stop Dependabot creating any more for the specific dependency's major version (unless you unignore this specific dependency's major version or upgrade to it yourself)
  • @dependabot ignore <dependency name> minor version will close this group update PR and stop Dependabot creating any more for the specific dependency's minor version (unless you unignore this specific dependency's minor version or upgrade to it yourself)
  • @dependabot ignore <dependency name> will close this group update PR and stop Dependabot creating any more for the specific dependency (unless you unignore this specific dependency or upgrade to it yourself)
  • @dependabot unignore <dependency name> will remove all of the ignore conditions of the specified dependency
  • @dependabot unignore <dependency name> <ignore condition> will remove the ignore condition of the specified dependency and ignore conditions

Bumps the prod-deps group with 6 updates:

| Package | From | To |
| --- | --- | --- |
| [org.tomlj:tomlj](https://github.com/tomlj/tomlj) | `2.0.1` | `2.1.1` |
| [com.h2database:h2-mvstore](https://github.com/h2database/h2database) | `2.5.250` | `2.5.252` |
| org.apache.commons:commons-lang3 | `3.20.0` | `3.21.0` |
| [org.apache.tika:tika-core](https://github.com/apache/tika) | `4.0.0` | `4.1.0` |
| [io.github.wasabithumb:jtoml](https://github.com/WasabiThumb/jtoml) | `1.8.0` | `1.8.1` |
| [io.github.wasabithumb:jtoml-serializer-gson](https://github.com/WasabiThumb/jtoml) | `1.8.0` | `1.8.1` |


Updates `org.tomlj:tomlj` from 2.0.1 to 2.1.1
- [Release notes](https://github.com/tomlj/tomlj/releases)
- [Commits](tomlj/tomlj@2.0.1...2.1.1)

Updates `com.h2database:h2-mvstore` from 2.5.250 to 2.5.252
- [Release notes](https://github.com/h2database/h2database/releases)
- [Commits](h2database/h2database@version-2.5.250...version-2.5.252)

Updates `org.apache.commons:commons-lang3` from 3.20.0 to 3.21.0

Updates `org.apache.tika:tika-core` from 4.0.0 to 4.1.0
- [Changelog](https://github.com/apache/tika/blob/main/CHANGES.txt)
- [Commits](apache/tika@4.0.0...4.1.0)

Updates `io.github.wasabithumb:jtoml` from 1.8.0 to 1.8.1
- [Release notes](https://github.com/WasabiThumb/jtoml/releases)
- [Commits](WasabiThumb/jtoml@1.8.0...1.8.1)

Updates `io.github.wasabithumb:jtoml-serializer-gson` from 1.8.0 to 1.8.1
- [Release notes](https://github.com/WasabiThumb/jtoml/releases)
- [Commits](WasabiThumb/jtoml@1.8.0...1.8.1)

---
updated-dependencies:
- dependency-name: org.tomlj:tomlj
  dependency-version: 2.1.1
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: prod-deps
- dependency-name: com.h2database:h2-mvstore
  dependency-version: 2.5.252
  dependency-type: direct:production
  update-type: version-update:semver-patch
  dependency-group: prod-deps
- dependency-name: org.apache.commons:commons-lang3
  dependency-version: 3.21.0
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: prod-deps
- dependency-name: org.apache.tika:tika-core
  dependency-version: 4.1.0
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: prod-deps
- dependency-name: io.github.wasabithumb:jtoml
  dependency-version: 1.8.1
  dependency-type: direct:production
  update-type: version-update:semver-patch
  dependency-group: prod-deps
- dependency-name: io.github.wasabithumb:jtoml-serializer-gson
  dependency-version: 1.8.1
  dependency-type: direct:production
  update-type: version-update:semver-patch
  dependency-group: prod-deps
...

Signed-off-by: dependabot[bot] <support@github.com>
@dependabot dependabot Bot added dependencies Pull requests that update a dependency file java Pull requests that update java code labels Sep 30, 2026
@sonarqubecloud

Copy link
Copy Markdown

@thmarx
thmarx merged commit b0a9856 into main Sep 30, 2026
3 checks passed
@dependabot
dependabot Bot deleted the dependabot/maven/prod-deps-bb1964247c branch September 30, 2026 12:00
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

dependencies Pull requests that update a dependency file java Pull requests that update java code

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant