OWASP / SecurityShepherd

Web and mobile application security training platform
https://owasp.org/www-project-security-shepherd/
GNU General Public License v3.0
1.34k stars 459 forks source link

Bump mariadb-java-client from 3.0.6 to 3.1.3 #755

Closed dependabot[bot] closed 1 year ago

dependabot[bot] commented 1 year ago

Bumps mariadb-java-client from 3.0.6 to 3.1.3.

Release notes

Sourced from mariadb-java-client's releases.

MariaDB Connector/Java 3.1.3

3.1.3 (Mar 2023)

Full Changelog

  • CONJ-1054 Threadsafety issue when using CredentialPlugin in v3.x
  • CONJ-1056 JDBC connector reads incorrect data from unix socket when the text is too large
  • CONJ-1057 Wrong decoding of binary time with value "00:00:00"
  • CONJ-1058 JDBC 4.3 org.mariadb.jdbc.Statement enquote* methods implementation @​peterhalicky
  • CONJ-1060 BIT default metadata doesn't take care of transformedBitIsBoolean option
  • report 2.7.9 bug fixes CONJ-1062 and CONJ-1063

MariaDB Connector/Java 3.1.2

3.1.2 (Jan 2023)

Full Changelog

  • CONJ-1040 possible ConcurrentModificationException when connecting
  • CONJ-1041 possible ArrayIndexOutOfBoundsException

MariaDB Connector/Java 3.1.1

3.1.1 (Jan 2023)

Full Changelog

  • 3.0.10 bug fix:
    • CONJ-1023 Connector/J doesn't set SSL cap bit in Handshake Response Packet
    • CONJ-1026 timezone=auto option failure on non-fixed-offset zone machine
    • CONJ-1032 Compatibility for deprecated arguments is case sensitive now
  • CONJ-1036 org.mariadb.jdbc.client.socket.impl.PacketWriter.writeAscii() broken in 3.1.0

MariaDB Connector/Java 3.0.10

3.0.10 (Jan 2023)

Full Changelog

  • CONJ-1023 Connector/J doesn't set SSL cap bit in Handshake Response Packet
  • CONJ-1026 timezone=auto option failure on non-fixed-offset zone machine
  • CONJ-1032 Compatibility for deprecated arguments is case sensitive now

MariaDB Connector/Java 3.0.9

3.0.9 (Nov 2022)

Full Changelog

  • 2.7.7 merge
  • CONJ-1012 stored procedure register output parameter as null if set before registerOutParameter command
  • CONJ-1017 Calendar possible race condition, cause wrong timestamp setting

MariaDB Connector/Java 3.0.8

3.0.8 (Sept 2022)

Full Changelog

Notable Changes
  • small performance improvement
    • [CONJ-1010] improve client side prepared parameter parameter substitution

... (truncated)

Changelog

Sourced from mariadb-java-client's changelog.

3.1.3 (Mar 2023)

Full Changelog

  • CONJ-1054 Threadsafety issue when using CredentialPlugin in v3.x
  • CONJ-1056 JDBC connector reads incorrect data from unix socket when the text is too large
  • CONJ-1057 Wrong decoding of binary time with value "00:00:00"
  • CONJ-1058 JDBC 4.3 org.mariadb.jdbc.Statement enquote* methods implementation @​peterhalicky
  • CONJ-1060 BIT default metadata doesn't take care of transformedBitIsBoolean option
  • report 2.7.9 bug fixes CONJ-1062 and CONJ-1063

2.7.9 (Mar 2023)

Full Changelog

  • CONJ-1062 correcting TlsSocketPlugin to use Driver classloader
  • CONJ-1063 DatabaseMetaData.getTypeInfo() returns wrong value for UNSIGNED_ATTRIBUTE

3.1.2 (Jan 2023)

Full Changelog

  • CONJ-1040 possible ConcurrentModificationException when connecting
  • CONJ-1041 possible ArrayIndexOutOfBoundsException

2.7.8 (Jan 2023)

Full Changelog

  • CONJ-1039 setQueryTimeout not honored by CallableStatement for procedures depending on security context
  • CONJ-1041 possible ArrayIndexOutOfBoundsException
  • CONJ-1023 set missing SSL capability in handshake after SSL exchanges

3.1.1 (Jan 2023)

Full Changelog

  • 3.0.10 bug fix:
    • CONJ-1023 Connector/J doesn't set SSL cap bit in Handshake Response Packet
    • CONJ-1026 timezone=auto option failure on non-fixed-offset zone machine
    • CONJ-1032 Compatibility for deprecated arguments is case sensitive now
  • CONJ-1036 org.mariadb.jdbc.client.socket.impl.PacketWriter.writeAscii() broken in 3.1.0

3.0.10 (Jan 2023)

Full Changelog

  • CONJ-1023 Connector/J doesn't set SSL cap bit in Handshake Response Packet
  • CONJ-1026 timezone=auto option failure on non-fixed-offset zone machine
  • CONJ-1032 Compatibility for deprecated arguments is case sensitive now

3.1.0 (Nov 2022)

Full Changelog

... (truncated)

Commits
  • d541afd bump 3.1.3
  • 5c77c28 [CONJ-1063] DatabaseMetaData.getTypeInfo() returns wrong value for UNSIGNED_A...
  • 4c018af [CONJ-1062] correcting TlsSocketPlugin to use Driver classloader
  • 3bae015 [CONJ-1063] DatabaseMetaData.getTypeInfo() returns wrong value for UNSIGNED_A...
  • c94cf0d [CONJ-1054] race condition when using CredentialPlugin
  • 016a211 [CONJ-1056] incorrect reads from unix socket when the text is too large
  • f6f5edc [CONJ-1058] code style correction for Statement.enquote* port from 2.x
  • e97a4ae Merge pull request #184 from peterhalicky/CONJ-1058
  • d2f936f [CONJ-1060] BIT default metadata doesn't take care of transformedBitIsBoolean...
  • a6007c7 bump SNAPSHOT version
  • Additional commits viewable in compare view


Dependabot compatibility score

Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting @dependabot rebase.


Dependabot commands and options
You can trigger Dependabot actions by commenting on this PR: - `@dependabot rebase` will rebase this PR - `@dependabot recreate` will recreate this PR, overwriting any edits that have been made to it - `@dependabot merge` will merge this PR after your CI passes on it - `@dependabot squash and merge` will squash and merge this PR after your CI passes on it - `@dependabot cancel merge` will cancel a previously requested merge and block automerging - `@dependabot reopen` will reopen this PR if it is closed - `@dependabot close` will close this PR and stop Dependabot recreating it. You can achieve the same result by closing it manually - `@dependabot ignore this major version` will close this PR and stop Dependabot creating any more for this major version (unless you reopen the PR or upgrade to it yourself) - `@dependabot ignore this minor version` will close this PR and stop Dependabot creating any more for this minor version (unless you reopen the PR or upgrade to it yourself) - `@dependabot ignore this dependency` will close this PR and stop Dependabot creating any more for this dependency (unless you reopen the PR or upgrade to it yourself)
dependabot[bot] commented 1 year ago

Superseded by #760.