DependencyTrack / dependency-track

Dependency-Track is an intelligent Component Analysis platform that allows organizations to identify and reduce risk in the software supply chain.
https://dependencytrack.org/
Apache License 2.0
2.45k stars 532 forks source link

Bump com.mysql:mysql-connector-j from 8.0.33 to 9.0.0 #3911

Open dependabot[bot] opened 6 days ago

dependabot[bot] commented 6 days ago

Bumps com.mysql:mysql-connector-j from 8.0.33 to 9.0.0.

Changelog

Sourced from com.mysql:mysql-connector-j's changelog.

Changelog

https://dev.mysql.com/doc/relnotes/connector-j/en/

Version 9.0.0

  • WL#16391, Upgrade 3rd party libraries and tools.

  • Fix for Bug#114800 (Bug#36576596), Wrong code by an old patch.

  • Fix for Bug#114846 (Bug#36574322), Auto-closeable X dev session. Thanks to Daniel Kec for his contribution.

  • Fix for Bug#114989 (Bug#36612566), Setting null value in setClientInfo throws an NPE.

  • WL#16376, Set 'caching_sha2_password' as default fallback authentication plugin.

  • WL#16342, Update MySQL error codes mapping.

  • WL#16353, Refresh the list of acceptable TLS ciphers.

  • Fix for Bug#114687 (Bug#36529541), Tests fail after mysql_native_password has been made optional in server.

  • WL#16319, Remove deprecated insensitive terminology based methods.

  • WL#16324, Update static MySQL keywords list.

  • Fix for Bug#110512 (Bug#35223851), Contribution: Replace synchronized with ReentrantLock. Thanks to Bart De Neuter and Janick Reynders for their contributions.

  • Fix for Bug#108830 (Bug#34721173), LIMIT clause, setMaxRows and cursor combined returns wrong number or rows.

Version 8.4.0

  • WL#15706, Add OpenTelemetry tracing.

  • WL#16174, Support for VECTOR data type.

  • Fix for Bug#36380711, Tests failing due to removal of deprecated features.

  • Fix for Bug#113600 (Bug#36171575), Contribution: Fix join condition for retrieval of imported primary keys. Thanks to Henning Pöttker for his contribution.

  • WL#16196, GPL License Exception Update.

  • Fix for Bug#111031 (Bug#35392222), Contribution: Update SyntaxRegressionTest.java. Thanks to Abby Palmero for her contribution.

  • Fix for Bug#113599 (Bug#36171571), Contribution: Replace StringBuffer with StringBuilder in ValueEncoders. Thanks to Henning Pöttker for his contribution.

... (truncated)

Commits
  • e0e8e34 Update fix for Bug#114687 (Bug#36529541), Tests fail after mysql_native_passw...
  • dd8a023 Update for GPL license book.
  • d3102b1 WL#16391, Upgrade 3rd party libraries and tools.
  • ce34ec8 Fix for Bug#114800 (Bug#36576596), Wrong code by an old patch.
  • a9ec867 Fix for Bug#114846 (Bug#36574322), Auto-closeable X dev session.
  • 223dfaf Fix for Bug#114989 (Bug#36612566), Setting null value in setClientInfo throws...
  • 39206fb WL#16376, Set 'caching_sha2_password' as default fallback authentication plugin.
  • 78451c4 WL#16342, Update MySQL error codes mapping.
  • bac0ea3 Merge remote-tracking branch 'origin/documentation/8.x' into 'version/9.x'.
  • 9533a6b WL#16353, Refresh the list of acceptable TLS ciphers.
  • Additional commits viewable in compare view


Dependabot compatibility score

Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting @dependabot rebase.


Dependabot commands and options
You can trigger Dependabot actions by commenting on this PR: - `@dependabot rebase` will rebase this PR - `@dependabot recreate` will recreate this PR, overwriting any edits that have been made to it - `@dependabot merge` will merge this PR after your CI passes on it - `@dependabot squash and merge` will squash and merge this PR after your CI passes on it - `@dependabot cancel merge` will cancel a previously requested merge and block automerging - `@dependabot reopen` will reopen this PR if it is closed - `@dependabot close` will close this PR and stop Dependabot recreating it. You can achieve the same result by closing it manually - `@dependabot show ignore conditions` will show all of the ignore conditions of the specified dependency - `@dependabot ignore this major version` will close this PR and stop Dependabot creating any more for this major version (unless you reopen the PR or upgrade to it yourself) - `@dependabot ignore this minor version` will close this PR and stop Dependabot creating any more for this minor version (unless you reopen the PR or upgrade to it yourself) - `@dependabot ignore this dependency` will close this PR and stop Dependabot creating any more for this dependency (unless you reopen the PR or upgrade to it yourself)