SamuelGuillemet / SEAK

SEAK, emulates a financial broker which allows you to buy and sell stocks at market price, place limit orders inside an order book and get the market data in real time.
5 stars 0 forks source link

⬆ Bump the gradle group with 11 updates #53

Closed dependabot[bot] closed 8 months ago

dependabot[bot] commented 8 months ago

Bumps the gradle group with 11 updates:

Package From To
org.apache.logging.log4j:log4j-api 2.22.1 2.23.1
org.apache.logging.log4j:log4j-core 2.22.1 2.23.1
org.apache.logging.log4j:log4j-slf4j2-impl 2.22.1 2.23.1
org.apache.logging.log4j:log4j-core 2.22.1 2.23.1
org.apache.logging.log4j:log4j-slf4j2-impl 2.22.1 2.23.1
com.fasterxml.jackson.dataformat:jackson-dataformat-yaml 2.16.1 2.16.2
com.fasterxml.jackson.core:jackson-databind 2.16.1 2.16.2
com.fasterxml.jackson.core:jackson-databind 2.16.1 2.16.2
org.postgresql:postgresql 42.7.1 42.7.2
org.springframework.security:spring-security-crypto 6.2.1 6.2.2
org.testcontainers:junit-jupiter 1.19.4 1.19.7
org.testcontainers:postgresql 1.19.4 1.19.7
org.testcontainers:kafka 1.19.4 1.19.7
org.testcontainers:testcontainers 1.19.4 1.19.7
org.testcontainers:postgresql 1.19.4 1.19.7
org.testcontainers:kafka 1.19.4 1.19.7
org.testcontainers:testcontainers 1.19.4 1.19.7

Updates org.apache.logging.log4j:log4j-api from 2.22.1 to 2.23.1

Updates org.apache.logging.log4j:log4j-core from 2.22.1 to 2.23.1

Updates org.apache.logging.log4j:log4j-slf4j2-impl from 2.22.1 to 2.23.1

Updates org.apache.logging.log4j:log4j-core from 2.22.1 to 2.23.1

Updates org.apache.logging.log4j:log4j-slf4j2-impl from 2.22.1 to 2.23.1

Updates com.fasterxml.jackson.dataformat:jackson-dataformat-yaml from 2.16.1 to 2.16.2

Commits
  • d4977eb [maven-release-plugin] prepare release jackson-dataformats-text-2.16.2
  • cd23e6c Prepare for 2.16.2 release
  • 55dd409 Merge branch '2.15' into 2.16
  • ef3e7ae Back to snapshot dep
  • 65cc7ec [maven-release-plugin] prepare for next development iteration
  • a133fd9 [maven-release-plugin] prepare release jackson-dataformats-text-2.15.4
  • d543cd0 Prepare for 2.15.4 release
  • 8a573e5 Back to snapshot dep
  • 201a86e [maven-release-plugin] prepare for next development iteration
  • See full diff in compare view


Updates com.fasterxml.jackson.core:jackson-databind from 2.16.1 to 2.16.2

Commits


Updates com.fasterxml.jackson.core:jackson-databind from 2.16.1 to 2.16.2

Commits


Updates org.postgresql:postgresql from 42.7.1 to 42.7.2

Release notes

Sourced from org.postgresql:postgresql's releases.

v42.7.2

Security

CVE-2024-1597 and Security Advisory addressed. The vulnerability occurs only in non-default preferQueryMode=simple mode and only if a negative place holder -? is used. See the security advisory for details

What's Changed

Full Changelog: https://github.com/pgjdbc/pgjdbc/compare/REL42.7.1...REL42.7.2

Changelog

Sourced from org.postgresql:postgresql's changelog.

[42.7.2] (2024-02-21 08:23:00 -0500)

Security

  • security: SQL Injection via line comment generation, it is possible in SimpleQuery mode to generate a line comment by having a placeholder for a numeric with a - such as -?. There must be second placeholder for a string immediately after. Setting the parameter to a -ve value creates a line comment. This has been fixed in this version fixes CVE-2024-1597. Reported by Paul Gerste. See the security advisory for more details. This has been fixed in versions 42.7.2, 42.6.1 42.5.5, 42.4.4, 42.3.9, 42.2.28.jre7. See the security advisory for work arounds.

Changed

Added

Commits
  • 06abfb7 Merge pull request from GHSA-24rp-q3w6-vc56
  • 93b0fcb Merge pull request from GHSA-24rp-q3w6-vc56
  • a408946 Revert "WIP speed up getDate (#3108)" (#3125)
  • f5d6e3f WIP speed up getDate (#3108)
  • 4e6a501 chore(deps): update release-drafter/release-drafter action to v6
  • 0b90367 chore(deps): update dependency gradle to v8.6
  • 4075f70 chore(deps): update oracle-actions/setup-java action to v1.3.3
  • 8de5beb fix(deps): update junit5 monorepo to v5.10.2
  • 6f741dd fix(deps): update dependency checkstyle to v10.13.0
  • 07e0535 fix(deps): update dependency com.github.spotbugs:com.github.spotbugs.gradle.p...
  • Additional commits viewable in compare view


Updates org.springframework.security:spring-security-crypto from 6.2.1 to 6.2.2

Release notes

Sourced from org.springframework.security:spring-security-crypto's releases.

6.2.2

:star: New Features

  • Configuration examples in docs are out of date #14392

:beetle: Bug Fixes

  • "Span wasn't started - an observation must be started (not only created)" (Micrometer) due to observation handling in Spring Security Web? #14568
  • HandlerMappingIntrospectorRequestTransformer is registered twice in AOT #14367
  • OAuth2AuthorizationExchange is not serializable #14405
  • WebTestUtilsTestRuntimeHints should implement RuntimeHintsRegistrar #14468
  • Application context fails to load: Couldn't find FilterChainProxy #14380
  • Back-Channel Logout should use localhost for internal logout request #14553
  • Cannot configure SecurityContextRepository in CasAuthenticationFilter #14536
  • Documentation about configuring SecuritySocketAcceptorInterceptor in Spring Boot is confusing #14348
  • fix typo in anonymous.adoc #14424
  • fix: typo in Authentication Architecture ProviderManager #14448
  • Missing native-image reflection hint for HandlerMappingIntrospectorCachFilterFactoryBean #14377
  • Missing native-image reflection hint for CsrfTokenRequestAttributeHandler$SupplierCsrfToken #14470
  • ReactiveMethodSecurityConfiguration is initialized prematurely when the context contains a BeanPostProcessor #14350
  • SAML relying party logout filter is always ordered last #14551
  • Spring Security 6.2 defaults to InMemoryOidcSessionRegistry causing memory leaks in distributed systems with external session storage #14558
  • Test using @WithMockUser fails with 401 UNAUTHORIZED with 3.2 #14207
  • Typo: Update authorize-http-requests.adoc #14563
  • Unexpected Exception Handling in NimbusReactiveJwtDecoder decode Method #14496
  • X-Xss-Protection header "1; mode=block" differs in Servlet and Reactive #14346

:hammer: Dependency Upgrades

  • Bump com.fasterxml.jackson:jackson-bom from 2.15.3 to 2.15.4 #14617
  • Bump Gamesight/slack-workflow-status from 1.2.0 to 1.3.0 #14582
  • Bump Gradle Wrapper from 8.5 to 8.6 #14547
  • Bump gradle/gradle-build-action from 2 to 3 #14503
  • Bump io-spring-javaformat from 0.0.40 to 0.0.41 #14439
  • Bump io.micrometer:micrometer-observation from 1.12.1 to 1.12.2 #14429
  • Bump io.micrometer:micrometer-observation from 1.12.2 to 1.12.3 #14589
  • Bump io.mockk:mockk from 1.13.8 to 1.13.9 #14412
  • Bump io.projectreactor:reactor-bom from 2023.0.1 to 2023.0.2 #14430
  • Bump io.projectreactor:reactor-bom from 2023.0.2 to 2023.0.3 #14612
  • Bump io.spring.ge.conventions from 0.0.14 to 0.0.15 #14463
  • Bump org-aspectj from 1.9.21 to 1.9.21.1 #14605
  • Bump org-eclipse-jetty from 11.0.18 to 11.0.19 #14354
  • Bump org-eclipse-jetty from 11.0.19 to 11.0.20 #14518
  • Bump org.apereo.cas.client:cas-client-core from 4.0.3 to 4.0.4 #14440
  • Bump org.jetbrains.kotlin:kotlin-bom from 1.9.21 to 1.9.22 #14364
  • Bump org.jetbrains.kotlin:kotlin-gradle-plugin from 1.9.21 to 1.9.22 #14363
  • Bump org.junit:junit-bom from 5.10.1 to 5.10.2 #14543
  • Bump org.slf4j:slf4j-api from 2.0.10 to 2.0.11 #14422
  • Bump org.slf4j:slf4j-api from 2.0.11 to 2.0.12 #14554
  • Bump org.slf4j:slf4j-api from 2.0.9 to 2.0.10 #14387

... (truncated)

Commits
  • 2cc6cbd Release 6.2.2
  • 15306c1 Merge branch '6.1.x' into 6.2.x
  • 750cb30 Add AuthenticationTrustResolver.isAuthenticated
  • 94f885c Merge branch '6.1.x' into 6.2.x
  • 3093908 Merge branch '5.8.x' into 6.1.x
  • 6230806 Change branch pattern
  • 60057a3 Bump org.springframework.data:spring-data-bom from 2023.1.2 to 2023.1.3
  • 5e7d6f8 Merge branch '6.1.x' into 6.2.x
  • ac87a1a Merge branch '5.8.x' into 6.1.x
  • 2159f3a Fix branch pattern
  • Additional commits viewable in compare view


Updates org.testcontainers:junit-jupiter from 1.19.4 to 1.19.7

Release notes

Sourced from org.testcontainers:junit-jupiter's releases.

1.19.7

Testcontainers for Java 1.19.7

Modules

Elasticserach

HiveMQ

MongoDB

  • Support mongodb/mongodb-community-server and mongodb/mongodb-enterprise-server (#8386) @​eddumelendez

PostgreSQL

📖 Documentation

📦 Dependency updates

1.19.6

Testcontainers for Java 1.19.6

Modules

New modules

📖 Documentation

... (truncated)

Commits


Updates org.testcontainers:postgresql from 1.19.4 to 1.19.7

Release notes

Sourced from org.testcontainers:postgresql's releases.

1.19.7

Testcontainers for Java 1.19.7

Modules

Elasticserach

HiveMQ

MongoDB

  • Support mongodb/mongodb-community-server and mongodb/mongodb-enterprise-server (#8386) @​eddumelendez

PostgreSQL

📖 Documentation

📦 Dependency updates

1.19.6

Testcontainers for Java 1.19.6

Modules

New modules

📖 Documentation

... (truncated)

Commits


Updates org.testcontainers:kafka from 1.19.4 to 1.19.7

Release notes

Sourced from org.testcontainers:kafka's releases.

1.19.7

Testcontainers for Java 1.19.7

Modules

Elasticserach

HiveMQ

MongoDB

  • Support mongodb/mongodb-community-server and mongodb/mongodb-enterprise-server (#8386) @​eddumelendez

PostgreSQL

📖 Documentation

📦 Dependency updates

1.19.6

Testcontainers for Java 1.19.6

Modules

New modules

📖 Documentation

... (truncated)

Commits


Updates org.testcontainers:testcontainers from 1.19.4 to 1.19.7

Release notes

Sourced from org.testcontainers:testcontainers's releases.

1.19.7

Testcontainers for Java 1.19.7

Modules

Elasticserach

HiveMQ

MongoDB

  • Support mongodb/mongodb-community-server and mongodb/mongodb-enterprise-server (#8386) @​eddumelendez

PostgreSQL

📖 Documentation

📦 Dependency updates

1.19.6

Testcontainers for Java 1.19.6

Modules

New modules

📖 Documentation

... (truncated)

Commits


Updates org.testcontainers:postgresql from 1.19.4 to 1.19.7

Release notes

Sourced from org.testcontainers:postgresql's releases.

1.19.7

Testcontainers for Java 1.19.7

Modules

Elasticserach

HiveMQ

MongoDB

  • Support mongodb/mongodb-community-server and mongodb/mongodb-enterprise-server (#8386) @​eddumelendez

PostgreSQL

📖 Documentation

📦 Dependency updates

1.19.6

Testcontainers for Java 1.19.6

Modules

New modules

📖 Documentation

... (truncated)

Commits


Updates org.testcontainers:kafka from 1.19.4 to 1.19.7

Release notes

Sourced from org.testcontainers:kafka's releases.

1.19.7

Testcontainers for Java 1.19.7

Modules

Elasticserach

HiveMQ

MongoDB

  • Support mongodb/mongodb-community-server and mongodb/mongodb-enterprise-server (#8386) @​eddumelendez

PostgreSQL

📖 Documentation

📦 Dependency updates

1.19.6

Testcontainers for Java 1.19.6

Modules

New modules

📖 Documentation

... (truncated)

Commits


Updates org.testcontainers:testcontainers from 1.19.4 to 1.19.7

Release notes

Sourced from org.testcontainers:testcontainers's releases.

1.19.7

Testcontainers for Java 1.19.7

Modules

Elasticserach

HiveMQ

MongoDB

  • Support mongodb/mongodb-community-server and mongodb/mongodb-enterprise-server (#8386) @​eddumelendez

PostgreSQL

📖 Documentation

📦 Dependency updates

  • Update docker-java version to 3.3.6 (#8410)
    dependabot[bot] commented 8 months ago

    Looks like these dependencies are updatable in another way, so this is no longer needed.