thumb-tack / tt

Apache License 2.0
0 stars 1 forks source link

Bump hibernate-core from 5.2.16.Final to 5.3.20.Final in /bom #42

Open dependabot[bot] opened 1 year ago

dependabot[bot] commented 1 year ago

Bumps hibernate-core from 5.2.16.Final to 5.3.20.Final.

Changelog

Sourced from hibernate-core's changelog.

Changes in 5.3.20.Final (November 16th, 2020)

https://hibernate.atlassian.net/projects/HHH/versions/31894/tab/release-report-all-issues

** Bug * [HHH-14257] - An Entity A with a map collection having as index an Embeddable with a an association to the Entity A fails with a NPE

** Task * [HHH-14225] - CVE-2020-25638 Potential for SQL injection on use_sql_comments logging enabled * [HHH-14324] - Add .gradletasknamecache to .gitignore

** Improvement * [HHH-14325] - Add Query hint for specifying "query spaces" for native queries

Changes in 5.3.19.Final (November 10th, 2020)

https://hibernate.atlassian.net/projects/HHH/versions/31874/tab/release-report-all-issues

** Bug * [HHH-13310] - getParameterValue() not working for collections * [HHH-14275] - Broken link to Infinispan User Guide in Hibernate 5.3 User Guide

** Task * [HHH-14309] - Improve BulkOperationCleanupAction#affectedEntity

** Sub-task * [HHH-14196] - Add parsing of persistence.xml/orm.xml documents in the EE 9 namespace

Changes in 5.3.18.Final (August 5th, 2020)

https://hibernate.atlassian.net/projects/HHH/versions/31849/tab/release-report-all-issues

** Bug * [HHH-12268] - LazyInitializationException thrown from lazy collection when batch fetching enabled and owning entity refreshed with lock * [HHH-13110] - @​PreUpdate method on a Embeddable null on the parent caused NullPointerException * [HHH-13936] - No auto transaction joining from SessionImpl.doFlush * [HHH-14077] - CVE-2019-14900 SQL injection issue using JPA Criteria API

** Task * [HHH-14013] - Upgrade to Hibernate Validator 6.0.20.Final * [HHH-14096] - Removal of unused code: XMLHelper and its SAXReader factory helper * [HHH-14103] - Add test cases showing that an entity's transient attribute can be overridden to be persistent in entity subclasses

Changes in 5.3.17.Final (April 30th, 2020)

... (truncated)

Commits
  • 64be512 5.3.20
  • bc8e38a HHH-14325 - Add Query hint for specifying "query spaces" for native queries
  • d5067ec HHH-14325 - Add Query hint for specifying "query spaces" for native queries
  • 2896372 HHH-14257 Add test for issue
  • 00b3ccb HHH-14257 An Entity A with a map collection having as index an Embeddable wit...
  • bf0b86d HHH-14324 Add .gradletasknamecache to .gitignore
  • d22bbb5 HHH-14225 CVE-2020-25638 Potential for SQL injection on use_sql_comments logg...
  • d48e19d 5.3.19
  • 3f3d38d 5.3.19
  • 23dd258 5.3.19
  • Additional commits viewable in compare view


Dependabot compatibility score

Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting @dependabot rebase.


Dependabot commands and options
You can trigger Dependabot actions by commenting on this PR: - `@dependabot rebase` will rebase this PR - `@dependabot recreate` will recreate this PR, overwriting any edits that have been made to it - `@dependabot merge` will merge this PR after your CI passes on it - `@dependabot squash and merge` will squash and merge this PR after your CI passes on it - `@dependabot cancel merge` will cancel a previously requested merge and block automerging - `@dependabot reopen` will reopen this PR if it is closed - `@dependabot close` will close this PR and stop Dependabot recreating it. You can achieve the same result by closing it manually - `@dependabot ignore this major version` will close this PR and stop Dependabot creating any more for this major version (unless you reopen the PR or upgrade to it yourself) - `@dependabot ignore this minor version` will close this PR and stop Dependabot creating any more for this minor version (unless you reopen the PR or upgrade to it yourself) - `@dependabot ignore this dependency` will close this PR and stop Dependabot creating any more for this dependency (unless you reopen the PR or upgrade to it yourself) - `@dependabot use these labels` will set the current labels as the default for future PRs for this repo and language - `@dependabot use these reviewers` will set the current reviewers as the default for future PRs for this repo and language - `@dependabot use these assignees` will set the current assignees as the default for future PRs for this repo and language - `@dependabot use this milestone` will set the current milestone as the default for future PRs for this repo and language You can disable automated security fix PRs for this repo from the [Security Alerts page](https://github.com/thumb-tack/tt/network/alerts).