gpp_maybe Security update for apache-commons-lang3, google-guice, maven, maven-resolver, xmvn
SUSE-SLE-Module-Basesystem-15-SP7-2026-3390


This update for apache-commons-lang3, google-guice, maven, maven-resolver, xmvn fixes the following issues: apache-commons-lang3 was updated to 3.20.0: * New features: + Add SystemProperties.getPath(String, Supplier<Path>) + Add JavaVersion.JAVA_25 + Add JavaVersion.JAVA_26 + Add SystemUtils.IS_JAVA_25 + Add SystemUtils.IS_JAVA_26 + Add MutablePair.ofNonNull(Map.Entry) + Add TimedSemaphore.builder(), Builder, and deprecate constructors + LANG-1504: Adding labels and history to split StopWatch * Fixed Bugs: + Optimize ObjectToStringComparator.compare() method + [javadoc] Improve StringUtils Javadoc + Fix internal inverted logic in private isEnum() method and correct its usage in getFirstEnum() + Use accessors in ToStringStyle so subclasses can effectively override them + 'LocaleUtils.toLocale(String)' for a 2 letter country code now returns a value instead of throwing an 'IllegalArgumentException' + Fix typo in StringUtils.trunctate() IllegalArgumentException message and test assertion messages + Fix test fixture in ReflectionDiffBuilderTest.testTransientFieldDifference() + LANG-1789: NullPointerException when generating NoSuchMethodException in MethodUtils + LANG-1786: Map deprecated TimeZone short IDs and avoid JRE WARNINGs to the console + LANG-1792: TypeUtils.toString() skips angle brackets for Class type + Mention JDK 25 LTS as a tested version in the release notes * Changes: + Bump org.apache.commons:commons-parent from 88 to 92 Update to 3.19.0: * New features: + Add ArrayUtils.SOFT_MAX_ARRAY_LENGTH + Add SystemUtils.IS_OS_NETWARE + Add MethodUtils.getAccessibleMethod(Class, Method) + Add documentation to site for CVE-2025-48924 ClassUtils.getClass(...) can throw a StackOverflowError on very long inputs + Add StringUtils.indexOfAny(CharSequence, int, char...) + Add ConcurrentException.ConcurrentException(String) + Add DateUtils.toLocalDateTime(Date[, TimeZone]) + Add DateUtils.toOffsetDateTime(Date[, TimeZone]) + Add DateUtils.toZonedDateTime(Date[, TimeZone]) + Add ByteConsumer + Add ByteSupplier + Add FailableByteConsumer + Add FailableByteSupplier + LANG-1784: Add Functions methods for null-safe mapping and chaining + LANG-1784: Add Failable methods for null-safe mapping and chaining + Add DoubleRange.fit(double) + Add IntegerRange.fit(int) + Add LongRange.fit(long) + Add DurationUtils.get(String, TemporalUnit, long) + Add DurationUtils.getMillis(String, long) + Add DurationUtils.getSeconds(String, long) + Add SystemProperties.getBoolean(Class, String, boolean) + Add SystemProperties.getInt(Class, String, int) + Add SystemProperties.getLong(Class, String, long) * Fixed Bugs: + LANG-1778: MethodUtils.getMatchingMethod() doesn't respect the hierarchy of methods + MethodUtils.getMethodObject(Class<?>, String, Class<?>...) now returns null instead of throwing a NullPointerException, as it does for other exception types + Reduce spurious failures in ArrayUtilsTest methods that test ArrayUtils.shuffle() methods + MethodUtils cannot find or invoke a public method on a public class implemented in its package-private superclass + AtomicSafeInitializer.get() can spin internally if the FailableSupplier given to AbstractConcurrentInitializer .AbstractBuilder.setInitializer(FailableSupplier) throws a RuntimeException + LANG-1783: WordUtils.containsAllWords?() may throw PatternSyntaxException + LANG-1782: MethodUtils cannot find or invoke vararg methods without providing vararg types or values + MethodUtils cannot find or invoke vararg methods of interface types + MethodUtils cannot find or invoke vararg methods when widening primitive types following the JLS 5.1.2. Widening Primitive Conversion + LANG-1597: Invocation fails because matching varargs method found but then discarded + Don't check accessibility twice in MemberUtils .setAccessibleWorkaround(T) + LANG-1774: Improve handling of ClassUtils .getShortCanonicalName() for invalid input + LANG-1720: Improve Javadocs for Conversion + Fix CalendarUtils.toLocalDate() Javadoc return type description + Fix the method name in Javadoc examples for CharUtils.isHex() + Deprecate NumberUtils.compare(byte, byte) in favor of Byte.compare(byte, byte) + Deprecate NumberUtils.compare(int, int) in favor of Integer.compare(int, int) + Deprecate NumberUtils.compare(long, long) in favor of Long.compare(long, long) + Deprecate NumberUtils.compare(short, short) in favor of Short.compare(short, short) + Deprecate obsolete system property constant SystemProperties.AWT_TOOLKIT + Deprecate obsolete system property constant SystemProperties.JAVA_AWT_FONTS + Deprecate obsolete system property constant SystemProperties.JAVA_AWT_GRAPHICSENV + Deprecate obsolete system property constant SystemProperties.JAVA_AWT_HEADLESS + Deprecate obsolete system property constant SystemProperties.JAVA_AWT_PRINTERJOB + Deprecate obsolete system property constant SystemProperties.JAVA_COMPILER + Deprecate obsolete system property constant SystemProperties.JAVA_ENDORSED_DIRS + Deprecate obsolete system property constant SystemProperties.JAVA_EXT_DIRS + Deprecate method for obsolete system property constant SystemProperties.getAwtToolkit() + Deprecate method for obsolete system property constant SystemProperties.getJavaAwtFonts() + Deprecate method for obsolete system property constant SystemProperties.getJavaAwtGraphicsenv() + Deprecate method for obsolete system property constant SystemProperties.getJavaAwtHeadless() + Deprecate method for obsolete system property constant SystemProperties.getJavaAwtPrinterjob() + Deprecate method for obsolete system property constant SystemProperties.getJavaCompiler() + Deprecate method for obsolete system property constant SystemProperties.getJavaEndorsedDirs() + Deprecate method for obsolete system property constant SystemProperties.getJavaExtDirs() + Deprecate method for obsolete system property constant SystemUtils.isJavaAwtHeadless() + Deprecate constants for obsolete system property SystemUtils.JAVA_AWT_FONTS + Deprecate constants for obsolete system property SystemUtils.JAVA_AWT_GRAPHICSENV + Deprecate constants for obsolete system property SystemUtils.JAVA_AWT_HEADLESS + Deprecate constants for obsolete system property SystemUtils.JAVA_AWT_PRINTERJOB + Deprecate constants for obsolete system property SystemUtils.JAVA_COMPILER + Deprecate constants for obsolete system property SystemUtils.JAVA_ENDORSED_DIRS + Deprecate constants for obsolete system property SystemUtils.JAVA_EXT_DIRS + [javadoc] General improvements + [javadoc] Fix thrown exception documentation for MethodUtils.getMethodObject(Class<?>, String, Class<?>...) + [javadoc] Strings::equalsAny: CI doc string should show it's insensitive + [javadoc] General Javadoc improvements + LANG-1780: [javadoc] Fix Strings Javadoc + [javadoc] Fix typo in Javadoc of Strings instances + [javadoc] Fix Javadocs in ClassUtils + [javadoc] Fix @deprecated link for StringUtils#startsWithAny + Replace old feather logotype with new oak logotype * Changes: + [test] Bump org.apache.commons:commons-text from 1.13.1 to 1.14.0 + Bump org.apache.commons:commons-parent from 85 to 88 Update to 3.18.0: - Fix component version in default.properties to 3.12 * Add and use LocaleUtils.toLocale(Locale) to avoid NPEs. * Add FailableShortSupplier, handy for JDBC APIs. * Add JavaVersion.JAVA_17. * Add StringUtils.substringBefore(String, int). * Add Range.INTEGER. * Add DurationUtils. * Correct implementation of RandomUtils.nextLong(long, long). * Update maven-surefire-plugin 2.22.2 -> 3.0.0-M5. * Bump junit-bom from 5.7.0 to 5.7.1. * Ignored exception 'ignored', should not be called so. * Change array style from 'int a[]' to 'int[] a'. google-guice was updated to fix: - Fix build with Java 25 - Add alias to com.google.inject:guice::classes artifact, needed by maven 4.x maven-resolver-supplier was updated to upstream version 1.9.27: * Bug Fixes + Sync TrackingFileManager with 2.x Update to upstream version 1.9.26: * New features and improvements + GH-1773: Treat 410 Gone as 404 Not Found + GH-1737: Revert partially parallel upload change * Bug Fixes + GH-1768; Drastically simplify auth caching + [1.9.x] Bug: GH-1703 Locally cached artifacts defy RRF * Documentation updates + Clarify that HTTP Transport uses Apache HTTP Client * Dependency updates + Bump org.redisson:redisson from 3.52.0 to 4.2.0 + Bump commons-codec:commons-codec from 1.20.0 to 1.21.0 + Bump org.codehaus.mojo:animal-sniffer-maven-plugin from 1.26 to 1.27 + Bump org.apache.maven:maven-parent from 46 to 47 + Bump com.github.siom79.japicmp:japicmp-maven-plugin from 0.25.0 to 0.25.4 + Bump mavenVersion from 3.9.11 to 3.9.12 - Update to upstream version 1.9.25 * New features and improvements + Add scope support for trusted checksums + Name mappers cleanup and new GAECV mapper + Proper metadata locking support + Ability to augment metadata nature for version range request * Bug Fixes + TrackingFileManager changes + Maven filters daemon friendly + Remove hack from Basic connector + Fix locking issues * Documentation updates + Updated the documentation to reflect the current list of name mappers * Maintenance + Mild backport: support same properties as Resolver 2.x + Maven resolver lockrepro + Bugfix: Java 25 broke test * Dependency updates + Bump com.github.siom79.japicmp:japicmp-maven-plugin from 0.23.1 to 0.25.0 + Bump org.codehaus.mojo:animal-sniffer-maven-plugin from 1.24 to 1.26 + Bump commons-codec:commons-codec from 1.18.0 to 1.20.0 + Bump org.redisson:redisson from 3.50.0 to 3.52.0 + Bump com.google.guava:guava from 33.4.8-jre to 33.5.0-jre + Bump com.google.code.gson:gson from 2.13.1 to 2.13.2 + Bump jettyVersion from 9.4.57.v20241219 to 9.4.58.v20250814 + Bump mavenVersion from 3.9.10 to 3.9.11 - Update to upstream version 1.9.24 * New features and improvements + Metadata type out of coordinates + RFC9457 implementation + Intern context strings * Maintenance + Align plexus-util version with Maven + Align guice version with Maven + Enable Github Issues (1.9.x branch) - Build also maven-resolver-supplier package in separate spec file - Add dependency on objectweb-asm to build with sisu 0.9.0.M4 - Update to upstream version 1.9.23 * Bug + MRESOLVER-659: NPE in trusted checksum post processor if * Improvement + MRESOLVER-680: Disable checksum by default for .sigstore.json as well + MRESOLVER-703: HTTP transport should expose config for max redirects - Upgrade to upstream version 1.9.22 * Bug + MRESOLVER-572: Resolver-Supplier unusable in OSGi runtimes + MRESOLVER-574: Invalid Cookie set under proxy conditions + MRESOLVER-586: In typical setups, DefaultArtifact copies the same maps over and over again + MRESOLVER-587: Memory consumption improvements * New Feature + MRESOLVER-571: Import o.e.aether packages with the exact same version in OSGi metadata * Improvement + MRESOLVER-570: Remove excessive strictness of OSGi dependency metadata * Task + MRESOLVER-576: Allow co-release of Resolver 1.x and 2.x - Upgrade to upstream version 1.9.20 * Bug + MRESOLVER-483: PreorderNodeListGenerator bug: may print trailing ":" + MRESOLVER-522: File locking threads not entering critical region were "oversleeping" + MRESOLVER-547: BF collector always copies artifacts, even when it should not * Improvement + MRESOLVER-536: Skip setting last modified time when FS does not support it - Add dependency on plexus-xml where relevant * this will be needed for smooth upgrade to plexus-utils 4.0.0 - Upgrade to upstream version 1.9.18 * Bug + MRESOLVER-372: Sporadic AccessDeniedEx on Windows + MRESOLVER-441: Undo FileUtils changes that altered non-Windows execution path * Improvement + MRESOLVER-396: Native transport should retry on HTTP 429 (Retry-After) * Task + MRESOLVER-397: Deprecate Guice modules + MRESOLVER-405: Get rid of component name string literals, make them constants and reusable + MRESOLVER-433: Expose configuration for inhibiting Expect-Continue handshake in 1.x + MRESOLVER-435: Refresh download page + MRESOLVER-437: Resolver should not override given HTTP transport default use of expect-continue handshake - Upgrade to upstream version 1.9.15 * Bug + MRESOLVER-373: Remove lock upgrading code + MRESOLVER-375: Several key aspects are broken in provided and trusted checksum feature + MRESOLVER-376: StackOverflowError at BfDependencyCollector.processDependency + MRESOLVER-380: Lock diagnostic: attempted lock step is recorded, but on failed attempt is not removed + MRESOLVER-393: Transport HTTP does not retain last modified as sent by remote end * Improvement + MRESOLVER-220: Modify signaling for unsupported operations + MRESOLVER-382: Define local outgoing (bind) address + MRESOLVER-385: Reduce default value for aether.connector.http.connectionMaxTtl * Task + MRESOLVER-378: Update parent POM to 40 + MRESOLVER-381: Undo MRESOLVER-373 as it was fixed by other means + MRESOLVER-386: Make all injected ctors public, deprecate all def ctors + MRESOLVER-388: Transport HTTP old codec proper override - Upgrade to upstream version 1.9.12 * Bug + [MRESOLVER-371] Unjustified WARNING log added by MRESOLVER-364 + [MRESOLVER-361] Unreliable TCP and retries on upload + [MRESOLVER-357] ConflictResolver STANDARD verbosity misbehaves + [MRESOLVER-352] Duplicate METADATA_DOWNLOADING event is being sent * Improvement + [MRESOLVER-360] disable checksum by default for .sigstore in addition to .asc * New Feature + [MRESOLVER-370] Lock factory should dump lock states on failure + [MRESOLVER-353] Make aether.checksums.algorithms settable per remote repository * Task + [MRESOLVER-366] Upgrade build plugins + [MRESOLVER-364] Revert MRESOLVER-132 + [MRESOLVER-359] Make build be explicit about build time requirements + [MRESOLVER-356] Remove Guava (is unused) + [MRESOLVER-354] Document expected checksums - Upgrade to upstream version 1.9.8 * Bug + [MRESOLVER-345] Conflict resolution in verbose mode is sensitive to version ordering + [MRESOLVER-348] SslConfig httpSecurityMode change is not detected + [MRESOLVER-339] Preemptive Auth broken when default ports used + [MRESOLVER-325] [REGRESSION] Suddenly seeing I/O errors under windows aborting the build + [MRESOLVER-330] Static name mapper is unusable with file-lock factory + [MRESOLVER-314] Getting "IllegalArgumentException: Comparison method violates its general contract!" + [MRESOLVER-316] DF collector enters endless loop when collecting org.webjars.npm:musquette:1.1.1 + [MRESOLVER-298] javax.inject should be provided or optional + [MRESOLVER-305] Evaluate blocked repositories also when retrieving metadata + [MRESOLVER-309] PrefixesRemoteRepositoryFilterSource aborts the build while it should not + [MRESOLVER-313] Artifact file permissions are 0600 and not implicitly set by umask + [MRESOLVER-296] FileProcessor.write( File, InputStream ) is defunct + [MRESOLVER-292] Documented and used param names mismatch + [MRESOLVER-294] Fix JapiCmp configuration and document it + [MRESOLVER-285] File locking on Windows knows to misbehave + [MRESOLVER-246] m-deploy-p will create hashes for hashes + [MRESOLVER-265] Discrepancy between produced and recognized checksums + [MRESOLVER-241] Resolver checksum calculation should be driven by layout + [MRESOLVER-242] When no remote checksums provided by layout, transfer inevitably fails/warns + [MRESOLVER-250] Usage of descriptors map in DataPool prevents gargabe collection * New Feature + [MRESOLVER-32] Support parallel artifact/metadata uploads + [MRESOLVER-319] Support parallel deploy + [MRESOLVER-297] Chained LRM + [MRESOLVER-167] Support forcing specific repositories for artifacts + [MRESOLVER-268] Apply artifact checksum verification for any resolved artifact + [MRESOLVER-274] Introduce Remote Repository Filter feature + [MRESOLVER-275] Introduce trusted checksums source + [MRESOLVER-276] Resolver post-processor + [MRESOLVER-278] BREAKING: Introduce RepositorySystem shutdown hooks + [MRESOLVER-236] Make it possible to resolve .asc on a 'fail' respository. * Improvement + [MRESOLVER-346] Too eager locking + [MRESOLVER-347] Better connection pool configuration (reuse, max TTL, maxPerRoute) + [MRESOLVER-349] Adapter when locking should "give up and retry" + [MRESOLVER-350] Get rid of commons-lang dependency + [MRESOLVER-327] Make tranport-http obey system properties regarding proxy settings + [MRESOLVER-340] Make WebDAV "dance" disabled by default + [MRESOLVER-341] Add option for preemptive PUT Auth + [MRESOLVER-315] Implement preemptive authentication feature for transport-http + [MRESOLVER-328] The transport-http should be able to ignore cert errors + [MRESOLVER-337] Real cause when artifact not found with repository filtering + [MRESOLVER-287] Get rid of deprecated finalize methods + [MRESOLVER-317] Improvements for BF collector + [MRESOLVER-318] Cleanup redundant code and centralize executor handling + [MRESOLVER-303] Make checksum detection reusable + [MRESOLVER-290] Improve file handling resolver wide + [MRESOLVER-7] Download dependency POMs in parallel in BF collector + [MRESOLVER-266] Simplify adapter creation and align configuration for it + [MRESOLVER-269] Allow more compact storage of provided checksums + [MRESOLVER-273] Create more compact File locking layout/mapper + [MRESOLVER-284] BREAKING: Some Sisu parameters needs to be bound + [MRESOLVER-286] Improve basic connector closed state handling + [MRESOLVER-240] Using breadth-first approach to resolve Maven dependencies + [MRESOLVER-247] Avoid unnecessary dependency resolution by a Skip solution based on BFS + [MRESOLVER-248] Make DF and BF collector implementations coexist * Task + [MRESOLVER-326] Resolver transport-http should retry on failures + [MRESOLVER-331] Make DefaultTrackingFileManager write directly to tracking files + [MRESOLVER-333] Distinguish better resolver errors for artifact availability + [MRESOLVER-320] Investigate slower resolving speeds as reported by users + [MRESOLVER-291] Undo MRESOLVER-284 + [MRESOLVER-279] Simplify and improve trusted checksum sources + [MRESOLVER-281] Update configurations page with new elements + [MRESOLVER-282] Drop PartialFile + [MRESOLVER-230] Make supported checksum algorithms extensible + [MRESOLVER-231] Extend “smart checksum” feature + [MRESOLVER-234] Introduce “provided” checksums feature + [MRESOLVER-237] Make all checksum mismatches handled same + [MRESOLVER-239] Update and sanitize dependencies + [MRESOLVER-244] Deprecate FileTransformer API + [MRESOLVER-245] Isolate Hazelcast tests * Dependency upgrade + [MRESOLVER-311] Upgrade Parent to 39 + [MRESOLVER-293] Update dependencies, align with Maven + [MRESOLVER-272] Update parent POM to 37, remove plugin version overrides, update bnd + [MRESOLVER-280] Upgrade invoker, install, deploy, require maven 3.8.4+ + [MRESOLVER-251] Upgrade Redisson to 3.17.5 + [MRESOLVER-249] Update Hazelcast to 5.1.1 in named-locks-hazelcast module - Add an alias for the wagon connector - Build against the standalone JavaEE modules unconditionally - Remove the javax.annotation:javax.annotation-api dependency on distribution versions that do not incorporate the JavaEE modules - Add the glassfish-annotation-api jar to the build classpath - Upgrade to upstream version 1.7.3 * Bug + [MRESOLVER-96] - Dependency Injection fails after upgrading to Maven 3.6.2 + [MRESOLVER-153] - resolver-status.properties file is corrupted due to concurrent writes + [MRESOLVER-171] - Resolver fails when compiled on Java 9+ an run on Java 8 due to JDK API breakage + [MRESOLVER-189] - Using semaphore-redisson followed by rwlock-redisson on many parallel build of the same project triggers redisson error * New Feature + [MRESOLVER-90] - HTML content in POM: Maven should validate content before storing in local repo + [MRESOLVER-145] - Introduce more SyncContext implementations * Improvement + [MRESOLVER-103] - Replace deprecated HttpClient classes + [MRESOLVER-104] - maven-resolver-demo-maven-plugin uses reserved artifactId + [MRESOLVER-147] - Upgrade to Java 8 + [MRESOLVER-148] - Use vanilla Guice 4 instead of forked Guice 3 + [MRESOLVER-156] - Active dependency management for Google Guice/Guava + [MRESOLVER-168] - add DEBUG message when downloading an artifact from repositories + [MRESOLVER-193] - Properly type lock key names in Redis + [MRESOLVER-197] - Minors improvements (umbrella) + [MRESOLVER-204] - Add a SessionData#computeIfAbsent method + [MRESOLVER-214] - Remove clirr configuration * Task + [MRESOLVER-141] - Review index-based access to collections + [MRESOLVER-151] - Enforce a checksum policy to be provided explicitly + [MRESOLVER-152] - Perform null checks when interface contracts require it + [MRESOLVER-154] - Move SyncContextFactory interface to SPI module + [MRESOLVER-155] - Make TrackingFileManager member of DefaultUpdateCheckManager + [MRESOLVER-158] - Simplify SimpleDigest class + [MRESOLVER-159] - Mark singleton components as Sisu Singletons + [MRESOLVER-160] - Deprecate ServiceLocator + [MRESOLVER-162] - Restore binary compatibility broken by MRESOLVER-154 + [MRESOLVER-170] - Deprecate org.eclipse.aether.spi.log + [MRESOLVER-172] - Make TrackingFileManager shared singleton component + [MRESOLVER-173] - Drop deprecated AetherModule + [MRESOLVER-174] - Use all bindings in UTs and tests + [MRESOLVER-175] - Drop SyncContextFactory delegates in favor of a selector approach + [MRESOLVER-177] - Move pre-/post-processing of metadata from ResolveTask to DefaultMetadataResolver + [MRESOLVER-183] - Don't require optional dependencies for Redisson + [MRESOLVER-184] - Destroy Redisson semaphores if not used anymore + [MRESOLVER-186] - Update Maven version in Resolver Demo Snippets + [MRESOLVER-188] - Improve documentation on using the named locks with redis/hazelcast (umbrella) + [MRESOLVER-190] - [Regression] Revert MRESOLVER-184 + [MRESOLVER-191] - Document how to analyze lock issues + [MRESOLVER-196] - Document named locks configuration options + [MRESOLVER-219] - Implement NamedLock with advisory file locking + [MRESOLVER-227] - Refactor NamedLockFactorySelector to a managed component + [MRESOLVER-232] - Make SimpleNamedLockFactorySelector logic reusable * Sub-task + [MRESOLVER-198] - Replace assert by simpler but equivalent calls + [MRESOLVER-199] - Java 8 improvements + [MRESOLVER-200] - Simplify conditions with the same result and avoid extra validations + [MRESOLVER-201] - Make variables final whenever possible + [MRESOLVER-202] - Use isEmpty() instead length() <= 0 * Dependency upgrade + [MRESOLVER-185] - Upgrade Redisson to 3.15.6 * Change of API and incompatible with maven-resolver < 1.7 - Upgrade to upstream version 1.6.3 * Bug + [MRESOLVER-153] - resolver-status.properties file is corrupted due to concurrent writes + [MRESOLVER-171] - Resolver fails when compiled on Java 9+ and run on Java 8 due to JDK API breakage * Improvement + [MRESOLVER-168] - add DEBUG message when downloading an artifact from repositories * Task + [MRESOLVER-177] - Move pre-/post-processing of metadata from ResolveTask to DefaultMetadataResolver * Needed for maven 3.8.4 - Do not build/run the tests against the legacy guava20 package - Upgrade to upstream version 1.6.2 * Sub-task + [MRESOLVER-139] - Make SimpleDigest use SHA-1 or MD5 only + [MRESOLVER-140] - Default to SHA-1 and MD5 hashing algorithms * Bug + [MRESOLVER-25] - Resume support is broken under high concurrency + [MRESOLVER-114] - ArtifactNotFoundExceptions when building in parallel + [MRESOLVER-129] - Exclusion has no setters + [MRESOLVER-137] - Make OSGi bundles reproducible + [MRESOLVER-138] - MRESOLVER-56 introduces severe performance regression * New Feature + [MRESOLVER-109] - AndDependencySelector should override toString + [MRESOLVER-115] - Make checksum algorithms configurable + [MRESOLVER-123] - Provide a global locking sync context by default + [MRESOLVER-131] - Introduce a Redisson-based SyncContextFactory + [MRESOLVER-165] - Add support for mirror selector on external:http:* + [MRESOLVER-166] - Add support for blocked repositories/mirrors * Improvement + [MRESOLVER-56] - Support SHA-256 and SHA-512 as checksums + [MRESOLVER-116] - Add page with all supported configuration options + [MRESOLVER-125] - Use type conversions returning primitives + [MRESOLVER-127] - Don't use boolean for property 'aether.updateCheckManager.sessionState' + [MRESOLVER-136] - Migrate from maven-bundle-plugin to bnd-maven-plugin * Task + [MRESOLVER-119] - Turn log messages to SLF4J placeholders + [MRESOLVER-130] - Move GlobalSyncContextFactory to a separate module + [MRESOLVER-132] - Remove synchronization in TrackingFileManager * Dependency upgrade + [MRESOLVER-105] - Update Plexus Components + [MRESOLVER-106] - Update HttpComponents + [MRESOLVER-107] - Update Wagon Provider API to 3.4.0 + [MRESOLVER-108] - Update mockito-core to 2.28.2 + [MRESOLVER-117] - Upgrade SLF4J to 1.7.30 + [MRESOLVER-118] - Upgrade Sisu Components to 0.3.4 * Needed for maven 3.8.x - Set buildshell to bash for "<<<". - Upgrade to upstream version 1.4.2 * Bug: + MRESOLVER-38 – SOE/OOME in DefaultDependencyNode.accept * Improvements: + MRESOLVER-93 – PathRecordingDependencyVisitor to handle 3 cycles + MRESOLVER-102 – make build Reproducible - Upgrade to upstream version 1.4.1 * Task + [MRESOLVER-92] - Revert MRESOLVER-7 * Bug + [MRESOLVER-86] - ResolveArtifactMojo from resolver example uses plugin repositories to resolve dependencies * New Feature + [MRESOLVER-10] - New 'TransitiveDependencyManager' supporting transitive dependency management + [MRESOLVER-33] - New 'DefaultDependencyManager' managing dependencies on all levels supporting transitive dependency management * Improvement + [MRESOLVER-7] - Download dependency POMs in parallel + [MRESOLVER-84] - Add support for "release" qualifier + [MRESOLVER-87] - Refresh examples to use maven-resolver artifacts for demo + [MRESOLVER-88] - Code style cleanup to use Java 7 features - Initial packaging of maven-resolver 1.3.1 - Generate and customize the ant build files maven-resolver was update to upstream version 1.9.27: * Bug Fixes + Sync TrackingFileManager with 2.x - Update to upstream version 1.9.26 * New features and improvements + GH-1773: Treat 410 Gone as 404 Not Found + GH-1737: Revert partially parallel upload change * Bug Fixes + GH-1768; Drastically simplify auth caching + [1.9.x] Bug: GH-1703 Locally cached artifacts defy RRF * Documentation updates + Clarify that HTTP Transport uses Apache HTTP Client * Dependency updates + Bump org.redisson:redisson from 3.52.0 to 4.2.0 + Bump commons-codec:commons-codec from 1.20.0 to 1.21.0 + Bump org.codehaus.mojo:animal-sniffer-maven-plugin from 1.26 to 1.27 + Bump org.apache.maven:maven-parent from 46 to 47 + Bump com.github.siom79.japicmp:japicmp-maven-plugin from 0.25.0 to 0.25.4 + Bump mavenVersion from 3.9.11 to 3.9.12 - Update to upstream version 1.9.25 * New features and improvements + Add scope support for trusted checksums + Name mappers cleanup and new GAECV mapper + Proper metadata locking support + Ability to augment metadata nature for version range request * Bug Fixes + TrackingFileManager changes + Maven filters daemon friendly + Remove hack from Basic connector + Fix locking issues * Documentation updates + Updated the documentation to reflect the current list of name mappers * Maintenance + Mild backport: support same properties as Resolver 2.x + Maven resolver lockrepro + Bugfix: Java 25 broke test * Dependency updates + Bump com.github.siom79.japicmp:japicmp-maven-plugin from 0.23.1 to 0.25.0 + Bump org.codehaus.mojo:animal-sniffer-maven-plugin from 1.24 to 1.26 + Bump commons-codec:commons-codec from 1.18.0 to 1.20.0 + Bump org.redisson:redisson from 3.50.0 to 3.52.0 + Bump com.google.guava:guava from 33.4.8-jre to 33.5.0-jre + Bump com.google.code.gson:gson from 2.13.1 to 2.13.2 + Bump jettyVersion from 9.4.57.v20241219 to 9.4.58.v20250814 + Bump mavenVersion from 3.9.10 to 3.9.11 - Update to upstream version 1.9.24 * New features and improvements + Metadata type out of coordinates + RFC9457 implementation + Intern context strings * Maintenance + Align plexus-util version with Maven + Align guice version with Maven + Enable Github Issues (1.9.x branch) - Build also maven-resolver-supplier package in separate spec file - Add dependency on objectweb-asm to build with sisu 0.9.0.M4 - Update to upstream version 1.9.23 * Bug + MRESOLVER-659: NPE in trusted checksum post processor if * Improvement + MRESOLVER-680: Disable checksum by default for .sigstore.json as well + MRESOLVER-703: HTTP transport should expose config for max redirects - Upgrade to upstream version 3.9.16 * Bug Fixes + Trim threadConfiguration to accept input surrounded with spaces + Backport: Maven 3.10.x fixed plugin resolution * Dependency updates + Bump org.codehaus.plexus:plexus-classworlds from 2.9.0 to 2.11.0 + [3.9.x] Bump to parent POM 48 + Bump commons-io:commons-io from 2.21.0 to 2.22.0 + Bump com.google.guava:guava from 33.5.0-jre to 33.6.0-jre + Bump actions/cache from 5.0.4 to 5.0.5 - There is no need to link the jansi-native library into the tree, since our jansi java library will load it from the system anyway - Upgrade to upstream version 3.9.15 * Documentation updates + Use new Maven logos in documentation + document modelVersion only supported value: 4.0.0 * Dependency updates + Bump actions/upload-artifact from 7.0.0 to 7.0.1 + Bump org.codehaus.plexus:plexus-utils from 3.6.0 to 3.6.1 + Bump org.fusesource.jansi:jansi from 2.4.2 to 2.4.3 + Bump actions/cache from 5.0.3 to 5.0.4 + Bump actions/download-artifact from 8.0.0 to 8.0.1 - Upgrade to upstream version 3.9.14 * Bug Fixes + plexus-testing dependencies should be used in test scope * Dependency updates + Bump actions/upload-artifact from 6.0.0 to 7.0.0 + Bump actions/download-artifact from 7.0.0 to 8.0.0 - Upgrade to upstream version 3.9.13 * Bug Fixes + Bug: SecDispatcher is managed by legacy Plexus DI + [3.9.x] MavenPluginJavaPrerequisiteChecker: Handle 8/1.8 Java version in ranges as well * Maintenance + Update Maven plugin versions in default-bindings.xml + Migrate to JUnit 5 - avoid using TestCase * Dependency updates + Maven Resolver 1.9.27 + Bump resolverVersion from 1.9.25 to 1.9.26 + Bump version.sisu-maven-plugin from 0.9.0.M4 to 1.0.0 + Bump actions/cache from 5.0.0 to 5.0.3 + Bump org.apache.maven:maven-parent from 45 to 47 + Bump actions/checkout from 6.0.1 to 6.0.2 + Bump actions/setup-java from 5.1.0 to 5.2.0 + Bump org.codehaus.mojo:animal-sniffer-maven-plugin from 1.26 to 1.27 + Bump org.codehaus.mojo:buildnumber-maven-plugin from 3.2.1 to 3.3.0 + Bump org.codehaus.plexus:plexus-testing from 2.0.2 to 2.1.0 + Bump org.ow2.asm:asm from 9.9 to 9.9.1 + Bump actions/upload-artifact from 5.0.0 to 6.0.0 + Bump actions/download-artifact from 6.0.0 to 7.0.0 - Specify required maven-resolver version since the maven-resolver-provider requires methods added in 1.9.25 - Upgrade to upstream version 3.9.12 * New features and improvements + Apply resolver changes and improvements + Update formatting of prerequisites-requirements error to improve readability + Allow a Maven plugin to require a Java version + Use MavenRepositorySystem in ProjectBuildingHelper instead of deprecated RepositorySystem + Make maven.config use UTF8 + Simplify prefix resolution * Bug Fixes + Add default implementation for new method in MavenPluginManager + Repository layout should be used in MavenRepositorySystem + Fix plugin prefix resolution when metadata is not available from repository + Improve source root modification warning message + Bug: bad cache isolation between two sessions + Set Guice class loading to CHILD - avoid using terminally deprecated methods + Avoid parsing MAVEN_OPTS (3.9.x) * Documentation updates + clarify repository vs deployment repository + add maintained branches * Maintenance + Add IntelliJ icon + Build by JDK 25 + Deprecate org.apache.maven.repository.RepositorySystem in 3.9.x * Build + Bump actions/download-artifact from 5.0.0 to 6.0.0 + Bump actions/upload-artifact from 4.6.2 to 5.0.0 * Dependency updates + Bump actions/cache from 4.2.3 to 5.0.0 + Bump resolverVersion from 1.9.24 to 1.9.25 + Bump actions/checkout from 5.0.0 to 6.0.1 + Bump actions/setup-java from 5.0.0 to 5.1.0 + Bump commons-cli:commons-cli from 1.9.0 to 1.11.0 + Bump org.codehaus.plexus:plexus-interpolation from 1.28 to 1.29 + Bump commons-io:commons-io from 2.19.0 to 2.21.0 + Bump xmlunitVersion from 2.10.3 to 2.11.0 + Bump org.codehaus.mojo:animal-sniffer-maven-plugin from 1.24 to 1.26 + Bump org.ow2.asm:asm from 9.8 to 9.9 + Bump com.google.guava:guava from 33.4.8-jre to 33.5.0-jre - Upgrade to upstream version 3.9.11 * New features and improvements + Augment version range resolution used repositories * Bug Fixes + Deduplicate filtered dependency graph + Move ensure in boundaries of project lock * Maintenance + [MNGSITE-393] - remove references to Maven 2 + Update CONTRIBUTING after GitHub issues enabled + Enable Github Issues + [MNG-8763] - Remove name from site bannerLeft * Build + Pin GitHub action versions by hash + Build the project by JDK 21 as default + Use Maven 3.9.10 for build on GitHub - Upgrade to upstream version 3.9.10 * Bug + MNG-8096: Inconsistent dependency resolution behaviour for concurrent multi-module build can cause failures + MNG-8169: MINGW support requires --add-opens java.base/java.lang=ALL-UNNAMED + MNG-8170: Maven 3.9.8 contains weird native library for Jansi on Windows/arm64 + MNG-8211: Maven should fail builds that use CI Friendly versions but have no values set + MNG-8248: WARNING: A restricted method in java.lang.System has been called + MNG-8256: ProjectDependencyGraph bug: in case of filtering, non-direct module links are lost + MNG-8315: Failure of mvn.cmd if a .mvn directory is located at drive root + MNG-8396: Maven takes forever to resume + MNG-8711: "Duplicate artifact" in LifecycleDependencyResolver * Improvement + MNG-8370: Introduce maven.repo.local.head + MNG-8399: JDK 24+ issues warning about usage of sun.misc.Unsafe + MNG-8707: Add methods to remove compile and test source roots + MNG-8712: improve dependency version explanation: it's a requirement, not always effective version + MNG-8717: Remove maven-plugin-plugin:addPluginArtifactMetadata from default binding + MNG-8722: Use a single standalone version of asm + MNG-8731: Use https for xsi:schemaLocation in generated descriptors + MNG-8734: Simplify scripting like "get project version" cases * Task + MNG-8728: Bump Eclipse Sisu from 0.9.0.M3 to 0.9.0.M4 and use Java 24 on CI - Link also the objectweb-asm/asm to the lib directory + MNG-8177: Warning xmvn-connector was updated to fix: - Add dependency on objectweb-asm to build with sisu 0.9.0.M4 - Upgrade to version 4.3.0 * Changes: + Fix typo in JavadocMojo + Reproducible javadoc + Reproducible manifest injection + Deprecate UUIDs + Implement MetadataResult.getPackageMetadataMap() xmvn-mojo was updated to fix: Upgrade to version 4.3.0 * Changes: + Fix typo in JavadocMojo + Reproducible javadoc + Reproducible manifest injection + Deprecate UUIDs + Implement MetadataResult.getPackageMetadataMap() xmvn-parent was updated to fix: - Upgrade to version 4.3.0 * Changes: + Fix typo in JavadocMojo + Reproducible javadoc + Reproducible manifest injection + Deprecate UUIDs + Implement MetadataResult.getPackageMetadataMap() xmvn-tools was updated to: - The new commons-compress needs commons-lang3 - Upgrade to version 4.3.0 * Changes: + Fix typo in JavadocMojo + Reproducible javadoc + Reproducible manifest injection + Deprecate UUIDs + Implement MetadataResult.getPackageMetadataMap() xmvn was updated to fix: - Adapt to no libjansi.so linked into the arch independent path - Fix build after removal of the default %%{java_home} define - Upgrade to version 4.3.0 * Changes: + Fix typo in JavadocMojo + Reproducible javadoc + Reproducible manifest injection + Deprecate UUIDs + Implement MetadataResult.getPackageMetadataMap()

  • Release Date
    Jul 28 2026
  • References
  • Type
    security
  • Severity
    important

cloud_download Downloads

Basesystem Module 15.7 s390x
  • Packages
    apache-commons-compress
    Java API for working with compressed files and archivers
    1.28.0-150200.3.21.1 lock rpm lock src
    apache-commons-lang3
    Apache Commons Lang Package
    3.20.0-150200.3.15.2 lock rpm lock src
Basesystem Module 15.7 ppc64le
  • Packages
    apache-commons-compress
    Java API for working with compressed files and archivers
    1.28.0-150200.3.21.1 lock rpm lock src
    apache-commons-lang3
    Apache Commons Lang Package
    3.20.0-150200.3.15.2 lock rpm lock src
Basesystem Module 15.7 aarch64
  • Packages
    apache-commons-compress
    Java API for working with compressed files and archivers
    1.28.0-150200.3.21.1 lock rpm lock src
    apache-commons-lang3
    Apache Commons Lang Package
    3.20.0-150200.3.15.2 lock rpm lock src
Basesystem Module 15.7 x86_64
  • Packages
    apache-commons-compress
    Java API for working with compressed files and archivers
    1.28.0-150200.3.21.1 lock rpm lock src
    apache-commons-lang3
    Apache Commons Lang Package
    3.20.0-150200.3.15.2 lock rpm lock src