Skip to content

fix(deps): update dependency com.networknt:json-schema-validator to v3 - #313

Open
renovate[bot] wants to merge 1 commit into
developmentfrom
renovate/com.networknt-json-schema-validator-3.x
Open

renovate[bot] wants to merge 1 commit into
developmentfrom
renovate/com.networknt-json-schema-validator-3.x

Conversation

@renovate

@renovate renovate Bot commented Dec 17, 2025 •

Copy link
Copy Markdown
Contributor

This PR contains the following updates:

Package Change Age Confidence
com.networknt:json-schema-validator 1.5.9 → 3.0.8 age confidence

Release Notes

networknt/json-schema-validator (com.networknt:json-schema-validator)

v3.0.8

Compare Source

Added
Changed
  • Expose Error.isCustomMessage() to identify messages supplied by the schema through the configured error message keyword, while preserving the existing Error constructor's binary compatibility and JSON serialization format. (680d7b3, f8c7659)
  • Reject leading or interior empty labels and names consisting only of label separators in the idn-hostname format (#​1274) Thanks @​dngr2
  • Allow apostrophes in uri-template literals (#​1275) Thanks @​dngr2
  • Honor PathType when formatting schema locations in DiscriminatorValidator exceptions (#​1281) Thanks @​youdie006
  • Resolve the OpenAPI nullable keyword through allOf/oneOf/anyOf, if/then/else and $ref/$dynamicRef/$recursiveRef ancestors, to any depth and in any order. nullable on a schema composed through these keywords now applies to the value they describe, for both the type and enum keywords (#​1278, #​1279, #​1283) Thanks @​tomakehurst
  • nullable on a container no longer applies to the values described by its properties, items and additionalProperties subschemas. Previously a nullable container made its children accept null. Schemas relying on that must declare nullable on the child itself. (#​1283) Thanks @​tomakehurst
  • oneOf no longer requires exactly one matching branch when the value is null and a nullable ancestor permits it. Every branch accepts null in that case, so {"nullable": true, "oneOf": [ ... ]} previously reported that more than one branch matched. Branch errors are still reported when no branch matches. (#​1283) Thanks @​tomakehurst
  • nullable no longer applies inside a not subschema, so {"nullable": true, "not": {"type": "string"}} now accepts null where it previously reported a not error. (#​1283) Thanks @​tomakehurst
  • With typeLoose enabled, the empty string no longer satisfies an enum on a nullable schema. null was previously held in the accepted set and compared as text, where it renders as the empty string, so {"enum": ["a"], "nullable": true} accepted "". Only an actual null is accepted now. (#​1283) Thanks @​tomakehurst
  • A nullable declared alongside $ref is now ignored at the root of an OpenAPI 3.0 schema as it already was elsewhere, so {"$ref": "...", "nullable": true} rejects null. Siblings of a Reference Object are ignored in OpenAPI 3.0. (#​1283) Thanks @​tomakehurst
  • Add regression coverage for YAML .nan, .inf and -.inf values producing validation type errors instead of parser exceptions with Jackson 3.2.1 (#​1228, #​1282) Thanks @​patpatpat123
  • Upgrade SLF4J from 2.0.17 to 2.0.19 and the test dependency Logback from 1.5.22 to 1.6.3. (759445b, 3d9971d, 2575a02)
  • Upgrade Maven Surefire and Surefire Report from 3.5.4 to 3.6.0, and the Central Publishing Maven plugin from 0.7.0 to 0.11.0. (f26327c, 4649209)
  • Upgrade the benchmark workflow to actions/checkout@v7 and actions/setup-java@v6. (6f5d6c1)

v3.0.7

Compare Source

Added
Changed

v3.0.6

Compare Source

Added
Changed

v3.0.5

Compare Source

Added
Changed
  • fixes #​1252 problem with additionalProperties schema in jsconfig schema (#​1253)
  • fixes #​1174 TextNodes as schema seem to validate any value (#​1250)

v3.0.4

Compare Source

Added
Changed

v3.0.3

Compare Source

Added
Changed

v3.0.2

Compare Source

Added
Changed

v3.0.1

Compare Source

Added
Changed

v3.0.0

Compare Source

Added
Changed

v2.0.8

Compare Source

2.0.8- 2026-10-01

Added
Changed
  • Resolve the OpenAPI nullable keyword through allOf/oneOf/anyOf, if/then/else and $ref/$dynamicRef/$recursiveRef ancestors, to any depth and in any order. nullable on a schema composed through these keywords now applies to the value they describe, for both the type and enum keywords.
  • nullable on a container no longer applies to the values described by its properties, items and additionalProperties subschemas. Previously a nullable container made an inline (non-$ref) child accept null. Schemas relying on that must declare nullable on the child itself.
  • oneOf no longer requires exactly one matching branch when the value is null and a nullable ancestor permits it. Every branch accepts null in that case, so {"nullable": true, "oneOf": [ ... ]} previously reported that more than one branch matched. Branch errors are still reported when no branch matches.
  • nullable no longer applies inside a not subschema, so {"nullable": true, "not": {"type": "string"}} now accepts null where it previously reported a not error.
  • With typeLoose enabled, the string "null" no longer satisfies an enum on a nullable schema. {"enum": ["a"], "nullable": true} previously accepted the string "null" as well as an actual null; only an actual null is accepted now.

v2.0.7

Compare Source

2.0.7- 2026-08-20

Added
Changed
  • Preserve binary compatibility for the Error constructor after adding custom-message metadata.

GitHub tag correction: this tag previously pointed to a 3.x commit on master. It now points to the verified 2.x release commit ae64ed637f743c4a88b2a391f20b639fe7f7d8e3, whose POM and all 222 published Java source files match Maven Central. The published Maven artifacts were already correct.

v2.0.6

Compare Source

2.0.6- 2026-08-20

Added
  • Add Error.isCustomMessage() to identify schema-supplied validation messages.
Changed

Restored missing GitHub tag and release. The release commit was verified against the existing Maven Central POM and all 222 published Java source files.

v2.0.5

Compare Source

2.0.5- 2026-08-20

Added
Changed
  • upgrade jackson to 2.22.1 to resolve a security vulnerability

GitHub tag correction: this tag previously pointed to a 3.x commit on master. It now points to the verified 2.x release commit 1fedf7133bb9ba4b41c7e3575abea01a6d5b61d0, whose POM and all 222 published Java source files match Maven Central. The published Maven artifacts were already correct.

v2.0.4

Compare Source

2.0.4- 2026-07-07

Added
Changed

GitHub tag correction: this tag previously pointed to a 3.x commit on master. It now points to the verified 2.x release commit 2ad25293fe9f28a43867b2e57fabb0a01f68317f, whose POM and all 222 published Java source files match Maven Central. The published Maven artifacts were already correct.

v2.0.3

Compare Source

2.0.3- 2026-06-23

Added
Changed
  • release with JDK 11
  • fixes 2.0.2 published jar is missing module-info.class — JPMS module com.networknt.schema no longer resolves

GitHub tag correction: this tag previously pointed to a 3.x commit on master. It now points to the verified 2.x release commit 8f2afe9090b1745b920fdbebf8f2a4f707eba0a5, whose POM and all 222 published Java source files match Maven Central. The published Maven artifacts were already correct.

v2.0.2

Compare Source

2.0.2- 2026-06-21

Added
Changed
  • fixes #​1248 validating draft4 schemas (#​1249)

  • fixes #​1248 validating draft4 schemas

  • Address regex factory review comments

  • Rename regex specification version variable

  • fixes #​1174 TextNodes as schema seem to validate any value (#​1250)

  • fixes #​1174 TextNodes as schema seem to validate any value

  • Address loaded schema validation for issue 1174

  • Address schema node validation review comments

  • Preserve mapped schema override path

  • Validate referenced document fragment schemas

  • Remove duplicate schema type validation

  • Validate loaded schemas for anchor refs

  • fixes #​1252 problem with additionalProperties schema in jsconfig schema (#​1253)

  • Add method to SpecificationVersion to determine from schema node (#​1221)

  • Manual adjustments for Jackson 2 compatibility and CVE fix

GitHub tag correction: this tag previously pointed to a 3.x commit on master. It now points to the verified 2.x release commit a3e58d9e55754e940277d2a1342bb1d3c2061e69, whose POM and all 222 published Java source files match Maven Central. The published Maven artifacts were already correct.

v2.0.1

Compare Source

Added
Changed

v2.0.0

Compare Source

Added
Changed

Configuration

📅 Schedule: (UTC)

  • Branch creation
    • At any time (no schedule defined)
  • Automerge
    • At any time (no schedule defined)

🚦 Automerge: Disabled by config. Please merge this manually once you are satisfied.

♻ Rebasing: Whenever PR becomes conflicted, or you tick the rebase/retry checkbox.

🔕 Ignore: Close this PR and you won't be reminded about this update again.


  • If you want to rebase/retry this PR, check this box

This PR was generated by Mend Renovate. View the repository job log.

@renovate renovate Bot added the dependencies Pull requests that update a dependency file label Dec 17, 2025
@coderabbitai

coderabbitai Bot commented Dec 17, 2025 •

Copy link
Copy Markdown
Contributor

Important

Review skipped

Bot user detected.

To trigger a single review, invoke the @coderabbitai review command.

⚙️ Run configuration
  • Configuration used: defaults
  • Review profile: CHILL
  • Plan: Advanced
  • Run ID: 6642479c-1df1-44f1-818d-3a70af456667

You can disable this status message by setting the reviews.review_status to false in the CodeRabbit configuration file.

Use the checkbox below for a quick retry:

  • 🔍 Trigger review
  • Autopilot · Keep fixing CodeRabbit findings and required CI, and resolving merge conflicts

Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out.

❤️ Share

Comment @coderabbitai help to get the list of available commands.

@renovate
renovate Bot force-pushed the renovate/com.networknt-json-schema-validator-3.x branch from 1e48423 to 8bb171a Compare March 13, 2026 22:15
@renovate
renovate Bot force-pushed the renovate/com.networknt-json-schema-validator-3.x branch from 8bb171a to 197d332 Compare April 18, 2026 01:42
@renovate
renovate Bot force-pushed the renovate/com.networknt-json-schema-validator-3.x branch from 197d332 to 9d3bb3c Compare May 31, 2026 00:29
@renovate
renovate Bot force-pushed the renovate/com.networknt-json-schema-validator-3.x branch from 9d3bb3c to e760956 Compare June 13, 2026 13:05
@renovate
renovate Bot force-pushed the renovate/com.networknt-json-schema-validator-3.x branch from e760956 to 2b5d00d Compare June 24, 2026 12:37
@Pfeil

Pfeil commented Jun 25, 2026

Copy link
Copy Markdown
Member

see #333

@renovate
renovate Bot force-pushed the renovate/com.networknt-json-schema-validator-3.x branch from 2b5d00d to e0d1eb9 Compare July 10, 2026 20:39
@renovate
renovate Bot force-pushed the renovate/com.networknt-json-schema-validator-3.x branch from e0d1eb9 to a9036a4 Compare July 20, 2026 20:43
@renovate
renovate Bot force-pushed the renovate/com.networknt-json-schema-validator-3.x branch 2 times, most recently from b2d56e6 to 659fc23 Compare August 20, 2026 14:45
@renovate
renovate Bot force-pushed the renovate/com.networknt-json-schema-validator-3.x branch from 659fc23 to f74d4c3 Compare August 23, 2026 22:34
@renovate
renovate Bot force-pushed the renovate/com.networknt-json-schema-validator-3.x branch from f74d4c3 to 6566dc7 Compare October 3, 2026 17:42
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

dependencies Pull requests that update a dependency file

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant