librespot-org / librespot-java

The most up-to-date open source Spotify client
Apache License 2.0
386 stars 95 forks source link

Bump io.undertow:undertow-core from 2.2.16.Final to 2.3.18.Final in /api #1000

Open dependabot[bot] opened 1 month ago

dependabot[bot] commented 1 month ago

Bumps io.undertow:undertow-core from 2.2.16.Final to 2.3.18.Final.

Release notes

Sourced from io.undertow:undertow-core's releases.

v2.3.17.Final

Includes CVEs: CVE-2024-7885

    Release Notes - Undertow - Version 2.3.17.Final

v2.3.16.Final

    Release Notes - Undertow - Version 2.3.16.Final

v2.3.14.Final

Includes CVES: CVE-2024-6162 CVE-2024-27316 CVE-2023-5685

    Release Notes - Undertow - Version 2.3.14.Final

... (truncated)

Commits
  • ac41e6e Prepare 2.3.18.Final
  • bde7c0a Merge pull request #1684 from baranowb/UNDERTOW-2333_2.3.x
  • 6d446ff [UNDERTOW-2333] Add websocket timeout testcase
  • 566df6d [UNDERTOW-2333] introduce WebSocket IO specific timeouts
  • e577596 Merge pull request #1687 from fl4via/backport-fixes_2.3.x
  • 4fe95e7 [UNDERTOW-2448] At ServletPrintWriter.write(CharBuffer) do not mark error if ...
  • 9990fbc [UNDERTOW-2444] Fix RST scenario violation in H2
  • 0c0ffc4 [UNDERTOW-2422] Return the protocol field of the HttpServerExchange into the ...
  • c37d94c [UNDERTOW-2436] fix HttpServerExchange state flag race conditions
  • b3ede9c [UNDERTOW-2446] HttpServletRequestImpl.getParts shouldn't throw exception aft...
  • Additional commits viewable in compare view


Dependabot compatibility score

Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting @dependabot rebase.


Dependabot commands and options
You can trigger Dependabot actions by commenting on this PR: - `@dependabot rebase` will rebase this PR - `@dependabot recreate` will recreate this PR, overwriting any edits that have been made to it - `@dependabot merge` will merge this PR after your CI passes on it - `@dependabot squash and merge` will squash and merge this PR after your CI passes on it - `@dependabot cancel merge` will cancel a previously requested merge and block automerging - `@dependabot reopen` will reopen this PR if it is closed - `@dependabot close` will close this PR and stop Dependabot recreating it. You can achieve the same result by closing it manually - `@dependabot show ignore conditions` will show all of the ignore conditions of the specified dependency - `@dependabot ignore this major version` will close this PR and stop Dependabot creating any more for this major version (unless you reopen the PR or upgrade to it yourself) - `@dependabot ignore this minor version` will close this PR and stop Dependabot creating any more for this minor version (unless you reopen the PR or upgrade to it yourself) - `@dependabot ignore this dependency` will close this PR and stop Dependabot creating any more for this dependency (unless you reopen the PR or upgrade to it yourself)