MikeSafonov / corporate-bot

MIT License
0 stars 4 forks source link

build(deps): bump hibernate-core from 5.5.3.Final to 5.6.4.Final #70

Closed dependabot[bot] closed 2 years ago

dependabot[bot] commented 2 years ago

Bumps hibernate-core from 5.5.3.Final to 5.6.4.Final.

Changelog

Sourced from hibernate-core's changelog.

Changes in 5.6.4.Final (January 19, 2022)

https://hibernate.atlassian.net/projects/HHH/versions/32012

** Bug * [HHH-15032] - Fix backwards incompatible SPI change that happened in 5.6.2 due to introducing SqlStringGenerationContext * [HHH-15022] - Bug After Upgrade Hibernate from 5.6.1.Final to 5.6.3.Final * [HHH-15002] - H2Dialect does not work properly with h2 2.0.202 and booleans types

** Task * [HHH-15036] - Disable DefaultCatalogAndSchemaTest when testing against MariaDB < 10.3 * [HHH-15033] - Restrict JNDI lookups to "java" scheme * [HHH-15031] - Upgrade to ByteBuddy 1.12.7 * [HHH-15028] - Upgrade to JBoss Logging 3.4.3.Final * [HHH-15026] - Upgrade to Log4J 2.17.1 * [HHH-15024] - Upgrade to Jandex 2.4.2.Final * [HHH-15018] - OracleTypesHelper shouldn't log stacktraces when the Oracle JDBC driver isn't loadable * [HHH-14998] - Upgrade to GraalVM 21.3.0 * [HHH-14988] - Upgrade to ByteBuddy 1.12.5 * [HHH-14987] - Upgrade to Log4j 2.17.0

Changes in 5.6.3.Final (December 15, 2021)

https://hibernate.atlassian.net/projects/HHH/versions/32006

** Bug * [HHH-14972] - log4j2 <= 2.14.1 has an RCE (CVE-2021-44228) * [HHH-14948] - Metamodel imports cache increases indefinitely for dynamically generated HQL aliases eventually leading to an OOM * [HHH-14935] - Type annotation is deprecated without an available replacement

** Task * [HHH-14979] - Upgrade to Log4J 2 2.16.0

Changes in 5.6.2.Final (December 08, 2021)

https://hibernate.atlassian.net/projects/HHH/versions/32001

** Bug * [HHH-14956] - Invalid link to MetadataBuilderContributor javadocs in Configurations docs * [HHH-14937] - SybaseDialect does not support schema anymore * [HHH-14936] - JdbcConnectionContext in hibernate-testing throws NPE when user/password are not provided in configuration * [HHH-14935] - Type annotation is deprecated without an available replacement * [HHH-14927] - "Current" documentation is 5.5 instead of 5.6 * [HHH-14926] - fix asciidoc error in 'test-case-guide.adoc' * [HHH-14922] - Inconsistent precedence of orm.xml implicit catalog/schema over "default_catalog"/"default_schema"

... (truncated)

Commits
  • 8f0a9c0 5.6.4.Final
  • bc3efea HHH-15036 Disable DefaultCatalogAndSchemaTest when testing against MariaDB < ...
  • 3427858 HHH-15022 Revert to the legacy behavior of not qualifying temporary ID tables...
  • 9dea484 HHH-15022 Test deleting all entities of a given type in a table-per-class hie...
  • ca2b8cb HHH-15032 Fix backwards incompatible SPI change that happened in 5.6.2 due to...
  • 30b0ad2 HHH-15033 Restrict JNDI lookups to "java" scheme
  • 1577160 HHH-15002 Add integration test for the H2 Dialect change
  • fdd4eb3 HHH-15031 Upgrade to ByteBuddy 1.12.7
  • be0f01a HHH-15028 Upgrade to JBoss Logging 3.4.3.Final
  • 3b94ea5 HHH-15026 Upgrade to Log4J 2.17.1
  • Additional commits viewable in compare view


Dependabot compatibility score

Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting @dependabot rebase.


Dependabot commands and options
You can trigger Dependabot actions by commenting on this PR: - `@dependabot rebase` will rebase this PR - `@dependabot recreate` will recreate this PR, overwriting any edits that have been made to it - `@dependabot merge` will merge this PR after your CI passes on it - `@dependabot squash and merge` will squash and merge this PR after your CI passes on it - `@dependabot cancel merge` will cancel a previously requested merge and block automerging - `@dependabot reopen` will reopen this PR if it is closed - `@dependabot close` will close this PR and stop Dependabot recreating it. You can achieve the same result by closing it manually - `@dependabot ignore this major version` will close this PR and stop Dependabot creating any more for this major version (unless you reopen the PR or upgrade to it yourself) - `@dependabot ignore this minor version` will close this PR and stop Dependabot creating any more for this minor version (unless you reopen the PR or upgrade to it yourself) - `@dependabot ignore this dependency` will close this PR and stop Dependabot creating any more for this dependency (unless you reopen the PR or upgrade to it yourself)
dependabot[bot] commented 2 years ago

Superseded by #71.