gocd / gocd-vault-secret-plugin

GoCD secrets plugin for HashiCorp's Vault
https://gocd.org
14 stars 7 forks source link

Bump jsoup from 1.13.1 to 1.14.3 #81

Closed dependabot[bot] closed 2 years ago

dependabot[bot] commented 2 years ago

Bumps jsoup from 1.13.1 to 1.14.3.

Release notes

Sourced from jsoup's releases.

jsoup 1.14.3

jsoup 1.14.3 is out now, adding native XPath selector support, improved \<template> support, and also includes a bunch of bug fixes, improvements, and performance enhancements.

See the release announcement for the full changelog.

jsoup 1.14.2

Caught by the fuzz! jsoup 1.14.2 is out now, and includes a set of parser bug fixes and improvements for handling rough HTML and XML, as identified by the Jazzer JVM fuzzer. This release also includes other fixes and improvements.

See the release announcement for the full changelog.

jsoup 1.14.1

jsoup 1.14.1 is out now, with simple request session management, increased parse robustness, and a ton of other improvements, speed-ups, and bug fixes.

See the full announcement for all the details on what's changed.

Changelog

Sourced from jsoup's changelog.

jsoup changelog

*** Release 1.15.1 [PENDING]

  • Change: removed previously deprecated methods and classes (including org.jsoup.safety.Whitelist; use org.jsoup.safety.Safelist instead).

  • Improvement: when converting jsoup Documents to W3C Documents in W3CDom, preserve HTML valid attribute names if the input document is using the HTML syntax. (Previously, would always coerce using the more restrictive XML syntax.) jhy/jsoup#1648

  • Improvement: added the :containsWholeText(text) selector, to match against non-normalized Element text. That can be useful when elements can only be distinguished by e.g. specific case, or leading whitespace, etc. jhy/jsoup#1636

  • Improvement: when evaluating an XPath query against a context element, the complete document is now visible to the query, vs only the context element's sub-tree. This enables support for queries outside (parent or sibling) the element, e.g. ancestor-or-self::*. jhy/jsoup#1652

  • Improvement: allow a maxPaddingWidth on the indent level in OutputSettings when pretty printing. This defaults to 30 to limit the indent level for very deeply nested elements, and may be disabled by setting to -1. jhy/jsoup#1655

  • Bugfix: boolean attribute names should be case-insensitive, but were not when the parser was configured to preserve case. jhy/jsoup#1656

  • Bugfix: when reading from SequenceInputStreams across the buffer, the input stream was closed too early, resulting in missed content. jhy/jsoup#1671

  • Bugfix: a comment with all dashes () should not emit a parse error. jhy/jsoup#1667

  • Bugfix: when throwing a SelectorParseException for an invalid selector, don't try to String.format the input, as that could throw an IllegalFormatException. jhy/jsoup#1691

  • Bugfix [Fuzz]: speed improvement when parsing constructed HTML containing very deeply incorrectly stacked formatting elements with many attributes. jhy/jsoup#1695

  • Bugfix [Fuzz]: during parsing, a StackOverflowException was possible given crafted HTML with hundreds of nested table elements followed by invalid formatting elements. jhy/jsoup#1697

*** Release 1.14.3 [2021-Sep-30]

  • Improvement: added native XPath support in Element#selectXpath(String) jhy/jsoup#1629

... (truncated)

Commits
  • 0006162 [maven-release-plugin] prepare release jsoup-1.14.3
  • 80a9396 Javadoc update for XPath
  • 0d1f04a Javadoc update to add @​since 1.14.3
  • 89de796 Bump junit-jupiter from 5.8.0 to 5.8.1 (#1645)
  • b14eb2a Test case and change note for parser improvements incl tag flyweight
  • 4b46397 Short-circuit tag scans for custom tags
  • d3f4e31 Flyweight Tag.valueOf in TreeBuilder
  • a8df71b Limit the stack depth we scan looking for mis-closed DD / DT tags
  • e4ae6fa Per spec, only foster incoming nodes if current node is a table foster target
  • 41932fe JDK 17 changelog
  • Additional commits viewable in compare view


Dependabot compatibility score

Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting @dependabot rebase.


Dependabot commands and options
You can trigger Dependabot actions by commenting on this PR: - `@dependabot rebase` will rebase this PR - `@dependabot recreate` will recreate this PR, overwriting any edits that have been made to it - `@dependabot merge` will merge this PR after your CI passes on it - `@dependabot squash and merge` will squash and merge this PR after your CI passes on it - `@dependabot cancel merge` will cancel a previously requested merge and block automerging - `@dependabot reopen` will reopen this PR if it is closed - `@dependabot close` will close this PR and stop Dependabot recreating it. You can achieve the same result by closing it manually - `@dependabot ignore this major version` will close this PR and stop Dependabot creating any more for this major version (unless you reopen the PR or upgrade to it yourself) - `@dependabot ignore this minor version` will close this PR and stop Dependabot creating any more for this minor version (unless you reopen the PR or upgrade to it yourself) - `@dependabot ignore this dependency` will close this PR and stop Dependabot creating any more for this dependency (unless you reopen the PR or upgrade to it yourself)