Bump org.assertj:assertj-core from 3.27.6 to 3.27.7 by dependabot[bot] 路 Pull Request #7126 路 micrometer-metrics/micrometer (original) (raw)
Bumps org.assertj:assertj-core from 3.27.6 to 3.27.7.
Release notes
Sourced from org.assertj:assertj-core's releases.
v3.27.7
馃敀 Security
Core
- Fix XXE vulnerability in
isXmlEqualToassertion (CVE-2026-24400)
- See GHSA-rqfh-9r24-8c9r for details; many thanks to @鈥媤xt201 and @鈥婼ong-Li for responsibly reporting it!
馃毇 Deprecated
Core
- Deprecate
XmlStringPrettyFormatterwith no replacement馃悰 Bug Fixes
Guava
- Navigation to
assertj-coreorguavatypes fromassertj-guavaJavadoc site has unnecessary header #3478馃敤 Dependency Upgrades
Core
- Upgrade to Byte Buddy 1.18.3
- Upgrade to JUnit BOM 5.14.1
Guava
- Upgrade to Guava 33.5.0-jre
Commits
- e840716 [maven-release-plugin] prepare release assertj-build-3.27.7
- 85ca7eb Deprecate
XmlStringPrettyFormatter - 77081dc Merge commit from fork
- b68fc24 Bump github/codeql-action from 4.31.9 to 4.31.10 in the github-actions group ...
- 0cf5bb6 Bump
kotlin.versionfrom 2.1.0 to 2.2.21 - d393ef1 Abort tests when symbolic links cannot be created (#3788)
- 2212433 Add IntelliJ custom inspection for test class names
- 5717d02 Update JetBrains icon
- a8ec20b Add icon for JetBrains products
- c05fb3d Bump Maven to 3.9.12 and Wrapper to 3.3.4
- Additional commits viewable in compare view
Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting @dependabot rebase.
Dependabot commands and options
You can trigger Dependabot actions by commenting on this PR:
@dependabot rebasewill rebase this PR@dependabot recreatewill recreate this PR, overwriting any edits that have been made to it@dependabot mergewill merge this PR after your CI passes on it@dependabot squash and mergewill squash and merge this PR after your CI passes on it@dependabot cancel mergewill cancel a previously requested merge and block automerging@dependabot reopenwill reopen this PR if it is closed@dependabot closewill close this PR and stop Dependabot recreating it. You can achieve the same result by closing it manually@dependabot show <dependency name> ignore conditionswill show all of the ignore conditions of the specified dependency@dependabot ignore this major versionwill close this PR and stop Dependabot creating any more for this major version (unless you reopen the PR or upgrade to it yourself)@dependabot ignore this minor versionwill close this PR and stop Dependabot creating any more for this minor version (unless you reopen the PR or upgrade to it yourself)@dependabot ignore this dependencywill close this PR and stop Dependabot creating any more for this dependency (unless you reopen the PR or upgrade to it yourself)