Skip to content

Conversation

@dependabot
Copy link

@dependabot dependabot bot commented on behalf of github Dec 12, 2025

Bumps jackrabbit.version from 2.23.2-beta to 2.23.3-beta.
Updates org.apache.jackrabbit:jackrabbit-jcr-server from 2.23.2-beta to 2.23.3-beta

Changelog

Sourced from org.apache.jackrabbit:jackrabbit-jcr-server's changelog.

Changes in Jackrabbit 2.23.3-beta

Sub-task

[JCR-5160] - Create jacoco reports compliant with SonarQube Cloud
[JCR-5172] - Exclude test sources from SonarQube analysis
[JCR-5173] - Create aggregate jacoco report
[JCR-5174] - Exclude jackrabbit-jcr-tests from coverage calculation

Bug

[JCR-5090] - Invalid href generated for 'Edit' buttons
[JCR-5141] - Deprecate org.apache.jackrabbit.commons.json
[JCR-5196] - Some test classes are not executed by default because they haven't been added to a test suite
[JCR-5203] - integration tests in jackrabbit-core occasionally fail to ItemNotFoundExceptions during cleanup

Improvement

[JCR-5154] - Replace deprecated call of Class.newInstance()

Task

[JCR-5140] - Improve support for generating namespace prefixes
[JCR-5156] - webapp: update tomcat dependency to 9.0.112
[JCR-5175] - Update Mockito dependency to 5.20.0
[JCR-5176] - Update commons-io dependency to 2.21.0
[JCR-5177] - jackrabbit-jcr2spi: update to commons-collections4 4.5.0
[JCR-5178] - Update easymock dependency to 5.6.0
[JCR-5179] - set baseline comparisonVersion to latest stable (2.22.1)
[JCR-5182] - Update pax-exam test dependency to 4.14.0
[JCR-5183] - Vote Template should be clear about the fact that running the check script in "sh" will not work
[JCR-5185] - Update oak-jackrabbit-api.version.implemented in trunk to Oak 1.86.0
[JCR-5187] - Update commons-cli dependency to 1.11.0
[JCR-5188] - Update h2db dependency to 2.3.232
[JCR-5189] - update Jetty to 9.4.58.v20250814
[JCR-5190] - webapp: bump htmlunit to 4.19.0
[JCR-5191] - remove JEXL dependency
[JCR-5192] - update aws java sdk version to 1.12.791
[JCR-5193] - update Apache parent pom to version 35
[JCR-5195] - Utilities for 'safe' creation of XML document builders
[JCR-5197] - cleanup o.a.j.util.Base64 and update Javadoc
[JCR-5200] - Update h2db dependency to 2.4.240
[JCR-5201] - Update oak-jackrabbit-api.version.implemented in trunk to Oak 1.88.0

For more detailed information about all the changes in this and other Jackrabbit releases, please see the Jackrabbit issue tracker at

... (truncated)

Commits
  • 8b55a53 [maven-release-plugin] prepare release jackrabbit-2.23.3-beta
  • bb1f7e3 Merge pull request #316 from apache/JCR-5212
  • 4e23bda JCR-5212 : updated release-notes
  • c1fc4a1 JCR-5187: Update commons-cli dependency to 1.11.0 (#314)
  • fd51c02 JCR-5190: webapp: bump htmlunit to 4.19.0 (#313)
  • d4da031 JCR-5156: webapp: update tomcat dependency to 9.0.112 (#312)
  • bc181ce JCR-5203: integration tests in jackrabbit-core occasionally fail to I… (#308)
  • 72e3ee7 JCR-5196: Some test classes are not executed by default because they … (#309)
  • 42566ae JCR-5197: cleanup o.a.j.util.Base64 and update Javadoc (#300)
  • 10d362c JCR-5176: Update commons-io dependency to 2.21.0 (#310)
  • Additional commits viewable in compare view

Updates org.apache.jackrabbit:jackrabbit-core from 2.23.2-beta to 2.23.3-beta

Changelog

Sourced from org.apache.jackrabbit:jackrabbit-core's changelog.

Changes in Jackrabbit 2.23.3-beta

Sub-task

[JCR-5160] - Create jacoco reports compliant with SonarQube Cloud
[JCR-5172] - Exclude test sources from SonarQube analysis
[JCR-5173] - Create aggregate jacoco report
[JCR-5174] - Exclude jackrabbit-jcr-tests from coverage calculation

Bug

[JCR-5090] - Invalid href generated for 'Edit' buttons
[JCR-5141] - Deprecate org.apache.jackrabbit.commons.json
[JCR-5196] - Some test classes are not executed by default because they haven't been added to a test suite
[JCR-5203] - integration tests in jackrabbit-core occasionally fail to ItemNotFoundExceptions during cleanup

Improvement

[JCR-5154] - Replace deprecated call of Class.newInstance()

Task

[JCR-5140] - Improve support for generating namespace prefixes
[JCR-5156] - webapp: update tomcat dependency to 9.0.112
[JCR-5175] - Update Mockito dependency to 5.20.0
[JCR-5176] - Update commons-io dependency to 2.21.0
[JCR-5177] - jackrabbit-jcr2spi: update to commons-collections4 4.5.0
[JCR-5178] - Update easymock dependency to 5.6.0
[JCR-5179] - set baseline comparisonVersion to latest stable (2.22.1)
[JCR-5182] - Update pax-exam test dependency to 4.14.0
[JCR-5183] - Vote Template should be clear about the fact that running the check script in "sh" will not work
[JCR-5185] - Update oak-jackrabbit-api.version.implemented in trunk to Oak 1.86.0
[JCR-5187] - Update commons-cli dependency to 1.11.0
[JCR-5188] - Update h2db dependency to 2.3.232
[JCR-5189] - update Jetty to 9.4.58.v20250814
[JCR-5190] - webapp: bump htmlunit to 4.19.0
[JCR-5191] - remove JEXL dependency
[JCR-5192] - update aws java sdk version to 1.12.791
[JCR-5193] - update Apache parent pom to version 35
[JCR-5195] - Utilities for 'safe' creation of XML document builders
[JCR-5197] - cleanup o.a.j.util.Base64 and update Javadoc
[JCR-5200] - Update h2db dependency to 2.4.240
[JCR-5201] - Update oak-jackrabbit-api.version.implemented in trunk to Oak 1.88.0

For more detailed information about all the changes in this and other Jackrabbit releases, please see the Jackrabbit issue tracker at

... (truncated)

Commits
  • 8b55a53 [maven-release-plugin] prepare release jackrabbit-2.23.3-beta
  • bb1f7e3 Merge pull request #316 from apache/JCR-5212
  • 4e23bda JCR-5212 : updated release-notes
  • c1fc4a1 JCR-5187: Update commons-cli dependency to 1.11.0 (#314)
  • fd51c02 JCR-5190: webapp: bump htmlunit to 4.19.0 (#313)
  • d4da031 JCR-5156: webapp: update tomcat dependency to 9.0.112 (#312)
  • bc181ce JCR-5203: integration tests in jackrabbit-core occasionally fail to I… (#308)
  • 72e3ee7 JCR-5196: Some test classes are not executed by default because they … (#309)
  • 42566ae JCR-5197: cleanup o.a.j.util.Base64 and update Javadoc (#300)
  • 10d362c JCR-5176: Update commons-io dependency to 2.21.0 (#310)
  • Additional commits viewable in compare view

Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting @dependabot rebase.


Dependabot commands and options

You can trigger Dependabot actions by commenting on this PR:

  • @dependabot rebase will rebase this PR
  • @dependabot recreate will recreate this PR, overwriting any edits that have been made to it
  • @dependabot merge will merge this PR after your CI passes on it
  • @dependabot squash and merge will squash and merge this PR after your CI passes on it
  • @dependabot cancel merge will cancel a previously requested merge and block automerging
  • @dependabot reopen will reopen this PR if it is closed
  • @dependabot close will close this PR and stop Dependabot recreating it. You can achieve the same result by closing it manually
  • @dependabot show <dependency name> ignore conditions will show all of the ignore conditions of the specified dependency
  • @dependabot ignore this major version will close this PR and stop Dependabot creating any more for this major version (unless you reopen the PR or upgrade to it yourself)
  • @dependabot ignore this minor version will close this PR and stop Dependabot creating any more for this minor version (unless you reopen the PR or upgrade to it yourself)
  • @dependabot ignore this dependency will close this PR and stop Dependabot creating any more for this dependency (unless you reopen the PR or upgrade to it yourself)

@dependabot dependabot bot added dependencies Pull requests that update a dependency file java Pull requests that update java code labels Dec 12, 2025
@JinwooHwang JinwooHwang force-pushed the 2.9.4-CVE-2025-66516-CVE-2025-54988 branch from 3caaace to 4c54360 Compare December 12, 2025 19:58
Dependabot couldn't find the original pull request head commit, b0db2e8.
@dependabot dependabot bot force-pushed the dependabot/maven/jackrabbit.version-2.23.3-beta branch from b0db2e8 to a6ce9d4 Compare December 12, 2025 19:59
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

dependencies Pull requests that update a dependency file java Pull requests that update java code

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant