Skip to content

Bump the gradle group across 1 directory with 2 updates#34

Open
dependabot[bot] wants to merge 1 commit intomasterfrom
dependabot/gradle/gradle-5ccf3babff
Open

Bump the gradle group across 1 directory with 2 updates#34
dependabot[bot] wants to merge 1 commit intomasterfrom
dependabot/gradle/gradle-5ccf3babff

Conversation

@dependabot
Copy link

@dependabot dependabot bot commented on behalf of github Mar 21, 2026

Bumps the gradle group with 2 updates in the / directory: org.springframework:spring-webmvc and io.undertow:undertow-core.

Updates org.springframework:spring-webmvc from 6.2.11 to 6.2.17

Release notes

Sourced from org.springframework:spring-webmvc's releases.

v6.2.17

⭐ New Features

  • Leverage ResourceHandlerUtils in ScriptTemplateView #36459
  • Restore ScriptTemplateViewTests #36457
  • Fix log message in ConfigurationClassBeanDefinitionReader #36454
  • Resolve context initializers only once in AbstractTestContextBootstrapper #36431
  • Exclude legacy @javax.validation.Constraint from convention-based annotation attribute override check #36412
  • Optimize MediaType(MediaType, Charset) constructor #36351
  • Optimize the addition of a charset to the MediaType in AbstractHttpMessageConverter #36350
  • Consistent adaptation of HTTP headers on Servlet responses #36345
  • Improve performance of validation groups determination in WebFlux #36337
  • Detect all common size exceptions from Tomcat and Commons FileUpload 2.x #36324

🐞 Bug Fixes

  • Guard against invalid id/event values in Server Sent Events #36442
  • Incomplete debug message in ConfigurationClassBeanDefinitionReader #36411
  • Inconsistent ApplicationEventMulticaster state after removing ApplicationListener implemented by FactoryBean #36405
  • Graceful shutdown of SimpleAsyncTaskExecutor #36384
  • HttpMediaTypeException thrown when calculating compatible media types #36363
  • ResolvableType#getGenerics() breaks serialization #36347
  • Multipart upload leak on client abort (ByteBuf.release() not called) #36327

📔 Documentation

  • Document @Fallback alongside Primary in the reference manual and @Bean Javadoc #36441
  • Document registration recommendations for BeanPostProcessor and BeanFactoryPostProcessor #36436
  • Fix links to UriComponentsBuilder and polish examples #36406
  • Emphasize @Configuration classes over XML and Groovy in testing chapter #36394
  • Polish SpEL operator examples in reference docs #36375

🔨 Dependency Upgrades

  • Upgrade to JUnit 5.14.3 #36388
  • Upgrade to Micrometer 1.15.10 #36446
  • Upgrade to Reactor 2024.0.16 #36445

v6.2.16

⭐ New Features

  • Improve performance of hashcode calculations for request mappings #36297
  • Improve performance of HandlerMethod bean lookup #36296
  • Improve performance of validation groups determination #36295
  • Improve performance of single pattern request mappings #36294
  • Optimize NamedParameterUtils#buildValueArray by lazily fetching SqlParameter #36232
  • Consistently close streams through try-with-resources in FileCopyUtils #36224
  • SqlBinaryValue and SqlCharacterValue should support InputStream content with undetermined length #36220
  • DataBufferUtils.write() with NettyDataBuffer on JDK 25 hangs indefinitely #36189
  • WebClient (Reactor) attributes on Netty channel do not clear after connection release #36163

... (truncated)

Commits
  • 4e35a12 Release v6.2.17
  • 317a1f9 Leverage ResourceHandlerUtils in ScriptTemplateView
  • de6601f Restore ScriptTemplateViewTests
  • 47dc1c4 Fix log message in ConfigurationClassBeanDefinitionReader
  • d8c7793 Upgrade to SnakeYAML 2.6, Protobuf 4.34, H2 2.4.240
  • 99fbce1 Polishing (aligned with main)
  • d1e69a9 Upgrade to Reactor 2024.0.16 and Micrometer 1.15.10
  • 8dc888e Guard against invalid id/event values in Server Sent Events
  • 131f94f Use link for first reference to @⁠Fallback in @⁠Bean Javadoc
  • d4f4c69 Document @​Fallback alongside Primary in the reference docs and @​Bean Javadoc
  • Additional commits viewable in compare view

Updates io.undertow:undertow-core from 2.3.20.Final to 2.3.21.Final

Release notes

Sourced from io.undertow:undertow-core's releases.

v2.3.21.Final

Release 2.3.21.Final fixes CVE-2024-3884 CVE-2024-4027 CVE-2025-12543 Full list of Jiras: view in Jira

    Release Notes - Undertow - Version 2.3.21.Final

... (truncated)

Commits
  • 791c908 Prepare 2.3.21.Final
  • 5374f57 Merge pull request #1862 from fl4via/backport-fixes_2.3.x
  • 7e25c8f [UNDERTOW-2609] Fix the since version in the @​Deprecated annotation at HttpSe...
  • bd97428 [UNDERTOW-2662] Remove the option to disable the RFC 6265 cookie parsing and ...
  • e45da52 Revert "[UNDERTOW-2675] Replace the new UndertowOptions by system properties ...
  • f60b476 Temporarily revert "[UNDERTOW-2662] Remove the option to disable the RFC 6265...
  • e47fed7 Temporarily revert "[UNDERTOW-2609] Fix the since version in the @​Deprecated ...
  • 6484e91 Merge pull request #1861 from fl4via/backport-fixes_2.3.x
  • 6e4b999 [UNDERTOW-2609] Fix the since version in the @​Deprecated annotation at HttpSe...
  • 2a7d993 [UNDERTOW-2421] Consolidate cookie attrib code and add support to attributes ...
  • Additional commits viewable in compare view

Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting @dependabot rebase.


Dependabot commands and options

You can trigger Dependabot actions by commenting on this PR:

  • @dependabot rebase will rebase this PR
  • @dependabot recreate will recreate this PR, overwriting any edits that have been made to it
  • @dependabot show <dependency name> ignore conditions will show all of the ignore conditions of the specified dependency
  • @dependabot ignore <dependency name> major version will close this group update PR and stop Dependabot creating any more for the specific dependency's major version (unless you unignore this specific dependency's major version or upgrade to it yourself)
  • @dependabot ignore <dependency name> minor version will close this group update PR and stop Dependabot creating any more for the specific dependency's minor version (unless you unignore this specific dependency's minor version or upgrade to it yourself)
  • @dependabot ignore <dependency name> will close this group update PR and stop Dependabot creating any more for the specific dependency (unless you unignore this specific dependency or upgrade to it yourself)
  • @dependabot unignore <dependency name> will remove all of the ignore conditions of the specified dependency
  • @dependabot unignore <dependency name> <ignore condition> will remove the ignore condition of the specified dependency and ignore conditions
    You can disable automated security fix PRs for this repo from the Security Alerts page.

Bumps the gradle group with 2 updates in the / directory: [org.springframework:spring-webmvc](https://github.com/spring-projects/spring-framework) and [io.undertow:undertow-core](https://github.com/undertow-io/undertow).


Updates `org.springframework:spring-webmvc` from 6.2.11 to 6.2.17
- [Release notes](https://github.com/spring-projects/spring-framework/releases)
- [Commits](spring-projects/spring-framework@v6.2.11...v6.2.17)

Updates `io.undertow:undertow-core` from 2.3.20.Final to 2.3.21.Final
- [Release notes](https://github.com/undertow-io/undertow/releases)
- [Commits](undertow-io/undertow@2.3.20.Final...2.3.21.Final)

---
updated-dependencies:
- dependency-name: org.springframework:spring-webmvc
  dependency-version: 6.2.17
  dependency-type: direct:production
  dependency-group: gradle
- dependency-name: io.undertow:undertow-core
  dependency-version: 2.3.21.Final
  dependency-type: direct:production
  dependency-group: gradle
...

Signed-off-by: dependabot[bot] <support@github.com>
@dependabot dependabot bot added dependencies Pull requests that update a dependency file java Pull requests that update java code labels Mar 21, 2026
@dependabot dependabot bot requested a review from a team as a code owner March 21, 2026 12:40
@dependabot dependabot bot added dependencies Pull requests that update a dependency file java Pull requests that update java code labels Mar 21, 2026
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

dependencies Pull requests that update a dependency file java Pull requests that update java code

Projects

None yet

Development

Successfully merging this pull request may close these issues.

0 participants