ArpNetworking / metrics-portal

2 stars 12 forks source link

Bump org.simplejavamail:simple-java-mail from 8.10.1 to 8.11.0 #709

Closed dependabot[bot] closed 5 months ago

dependabot[bot] commented 5 months ago

Bumps org.simplejavamail:simple-java-mail from 8.10.1 to 8.11.0.

Release notes

Sourced from org.simplejavamail:simple-java-mail's releases.

v8.11.0

#526: When reading .msg files the RTF converted to HTML is garbled in some cases where the appropriate charset is not detected properly

NOTE: this release contains many (minor) dependency updates to resolve CVE issues, including:

  • parent POM upgrade: Upgrades test dependencies as well as SLF4J versions
  • outlook-message-parser 1.13.2 -> 1.14.0
  • java-reflection 4.0.1 -> 4.0.2
  • smtp-connection-pool 2.3.1 -> 2.3.2
  • utils-mail-dkim 3.1.0 -> 3.2.0
  • jakarta.mail-api 2.1.2 -> 2.1.3
  • angus-mail 2.0.2 -> 2.0.3
  • therapi-runtime-javadoc 0.13.0 -> 0.15.0
  • kryo 5.0.0-RC1 -> 5.6.0
  • maven-assembly-plugin 3.1.0 -> 3.7.1 (only for the CLI module during build)
Changelog

Sourced from org.simplejavamail:simple-java-mail's changelog.

v8.11.0 (25-May-2024)

  • #526: When reading .msg files the RTF converted to HTML is garbled in some cases where the appropriate charset is not detected properly

NOTE: this release contains many (minor) dependency updates to resolve CVE issues, including: - parent POM upgrade: Upgrades test dependencies as well as SLF4J versions - outlook-message-parser 1.13.2 -> 1.14.0 - java-reflection 4.0.1 -> 4.0.2 - smtp-connection-pool 2.3.1 -> 2.3.2 - utils-mail-dkim 3.1.0 -> 3.2.0 - jakarta.mail-api 2.1.2 -> 2.1.3 - angus-mail 2.0.2 -> 2.0.3 - therapi-runtime-javadoc 0.13.0 -> 0.15.0 - kryo 5.0.0-RC1 -> 5.6.0 - maven-assembly-plugin 3.1.0 -> 3.7.1 (only for the CLI module during build)

v8.10.0 - v8.10.1

  • v8.10.1 (04-May-2024): #510: Update upstream dependency generic-object-pool, which solves a critical bug when there are exceptions during allocation
  • v8.10.0 (30-April-2024): #508: [enhancement+bug] Make EmailConverter API more consistent regarding Session parameter, don't use Session.getDefaultInstance anymore and fix bug where emlToEmailBuilder used emlToMimeMessage

v8.10.0 (30-April-2024)

  • #508: [enhancement+bug] Make EmailConverter API more consistent regarding Session parameter, don't use Session.getDefaultInstance anymore and fix bug where emlToEmailBuilder used emlToMimeMessage

v8.9.0 (26-April-2024)

  • #507: [security] Update 3rd party dependencies to get rid of all currently known CVE issues (see issue for details)

v8.8.0 - v8.8.4

  • v8.8.4 (23-April-2024): #506: Upgrade utils-mail-smime dependency to 2.3.2, to resolve CVE issue in bouncycastle
  • v8.8.3 (13-April-2024): #502: [Bug] Message headers not treated with case insensitivity as per RFC, causing deviating headers to slip through the filters
  • v8.8.2 (05-April-2024): #495: Add config support for 'verifyingServerIdentity' with SMTP, also: since Angus 1.1.0 server identity checks are on by default and can be countered by mailerBuilder.verifyingServerIdentity(false)
  • v8.8.2 (05-April-2024): #501: [dependency] Update outlook-message-parser dependency, which has improved support for X500 addresses
  • v8.8.1 (04-April-2024): #500: [bug] Fix parsing addresses from headers in EML files, like a Disposition-Notification-To with umlaut
  • v8.8.0 (22-March-2024): #499: [Enhancement] Expose finer-grained DKIM configuration through the builder api and disable 'l-param' by default)

NOTE: this release changes the default for DKIM signing from 'l-param' true to false. If you rely on this feature, you need to enable it explicitly (see the updated https://www.simplejavamail.org/security.html#section-sending-dkim).

v8.7.0 - v8.7.1

  • v8.7.1 (20-March-2024): #498: [Enhancement] Make S/MIME algorithms configurable (signature algorithm for signing, key encapsulation and cipher algorithms for encryption)
  • v8.7.1 (20-March-2024): #497: [Bug] Order of attachments is lost when converting a MimeMessage to an Email
  • v8.7.0 (20-March-2024): don't use this version: versioning messed up

... (truncated)

Commits
  • 7a6874e released 8.11.0 [skip ci]
  • 23f2319 Added missing cli data files
  • 26a6a95 fixed a few typos [skip ci]
  • bc975ad Going straight to release 8.11.0 instead
  • 5bde25f Solving SpotBugs warning about nullable / nonnullable method result
  • ba052e5 Merge branch 'refs/heads/develop'
  • a3a7a54 #526: Updated outlook-message-parser from 1.13.2 to 1.14.0 which fixes a char...
  • edea92e Upgrading release pipeline which switches to the newer next-gen convenience i...
  • 0fac5c3 Upgrade parent pom to fix logging dependency during junit tests / demo app runs
  • 9deafc4 remove async demo example as it keeps the JVM alive
  • Additional commits viewable in compare view


Dependabot compatibility score

Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting @dependabot rebase.


Dependabot commands and options
You can trigger Dependabot actions by commenting on this PR: - `@dependabot rebase` will rebase this PR - `@dependabot recreate` will recreate this PR, overwriting any edits that have been made to it - `@dependabot merge` will merge this PR after your CI passes on it - `@dependabot squash and merge` will squash and merge this PR after your CI passes on it - `@dependabot cancel merge` will cancel a previously requested merge and block automerging - `@dependabot reopen` will reopen this PR if it is closed - `@dependabot close` will close this PR and stop Dependabot recreating it. You can achieve the same result by closing it manually - `@dependabot show ignore conditions` will show all of the ignore conditions of the specified dependency - `@dependabot ignore this major version` will close this PR and stop Dependabot creating any more for this major version (unless you reopen the PR or upgrade to it yourself) - `@dependabot ignore this minor version` will close this PR and stop Dependabot creating any more for this minor version (unless you reopen the PR or upgrade to it yourself) - `@dependabot ignore this dependency` will close this PR and stop Dependabot creating any more for this dependency (unless you reopen the PR or upgrade to it yourself)
dependabot[bot] commented 5 months ago

Superseded by #710.