To pat ourselves on the back a bit, one reason the length of these reports
hasn't gone down much since, say, 2023, is we now have a bunch of suggested
EE API updates (13 of them), and that's because the EE 11 APIs were
released last year. And that's fine; those will show up on the report in a
block and we can just ignore the minor updates. (We provide most of these
in WF Preview.)
On Wed, Apr 2, 2025 at 11:10 AM Brian Stansberry <bstansbe(a)redhat.com>
wrote:
Hey everyone,
Just a gentle reminder to keep an eye on these reports.
Dependabot has been working hard on sending up micro-update PRs for a long
time now, and over time the number of unaddressed micros is going down*,
but the overall length of this report isn't shrinking much.
This is because we are starting to have a lot of cases where there is a
newer minor version out there than we are using. Please keep in mind that
dependabot is not configured to suggest minor updates (and it won't be
configured that way.) These emails should help developers be aware of new
minors so they can possibly take action based on their own knowledge of how
these libraries are used.
Note I'm not calling here for a general 'let's reduce the report size'
drive or pushing for any particular upgrade. This is just a gentle reminder.
* To be fair *I think* this week's report has more micro updates on it
than has been the recent case. So I expect we'll see more dependabot PRs
soon, unless something has gone awry.
On Wed, Apr 2, 2025 at 10:49 AM Tomas Hofman via wildfly-dev <
wildfly-dev(a)lists.jboss.org> wrote:
> Component Upgrade Report
>
> Following repositories were searched:
>
> - Central
https://repo1.maven.org/maven2/
> - JBossPublic
>
https://repository.jboss.org/nexus/content/repositories/public/
>
> Possible Component Upgrades
> GAVNew VersionRepositorySince
> com.fasterxml:classmate:1.5.1
> ↳ Minor upgrade 1.7.0 Central 2024-02-07
> com.fasterxml.woodstox:woodstox-core:7.0.0
> ↳ Minor upgrade 7.1.0 Central 2024-10-23
> com.google.api.grpc:proto-google-common-protos:2.0.1
> ↳ Minor upgrade 2.54.1 Central 2025-03-19
> com.google.code.gson:gson:2.8.9
> ↳ Minor upgrade 2.12.1 Central 2025-02-05
> com.google.guava:guava:33.0.0-jre
> ↳ Minor upgrade 33.4.6-jre Central 2025-03-26
> com.google.protobuf:protobuf-java:4.28.3
> ↳ Minor upgrade 4.30.2 Central new
> com.h2database:h2:2.2.224
> ↳ Minor upgrade 2.3.232 Central 2024-08-14
> com.nimbusds:nimbus-jose-jwt:9.37.3
> ↳ Minor upgrade 9.48 Central 2024-12-25
> ↳ Very latest 10.0.2 Central 2025-02-26
> com.sun.istack:istack-commons-runtime:4.1.2
> ↳ Minor upgrade 4.2.0 Central 2024-02-07
> com.sun.xml.messaging.saaj:saaj-impl:3.0.0 3.0.4 Central 2024-05-22
> commons-beanutils:commons-beanutils:1.9.4
> ↳ Minor upgrade 1.10.1 Central 2025-02-19
> commons-codec:commons-codec:1.17.2
> ↳ Minor upgrade 1.18.0 Central 2025-01-29
> commons-collections:commons-collections:3.2.2
> ↳ Very latest 20040616 Central 2024-02-07
> commons-io:commons-io:2.16.1
> ↳ Minor upgrade 2.18.0 Central 2024-11-20
> de.dentrassi.crypto:pem-keystore:2.4.0
> ↳ Very latest 3.0.0 Central 2024-11-20
> io.agroal:agroal-api:2.0
> ↳ Minor upgrade 2.6 Central new
> io.github.resilience4j:resilience4j-core:2.2.0
> ↳ Minor upgrade 2.3.0 Central 2025-01-08
> io.grpc:grpc-api:1.70.0
> ↳ Minor upgrade 1.71.0 Central 2025-03-05
> io.netty:netty-all:4.0.19.Final 4.0.56.Final Central 2024-02-07
> ↳ Minor upgrade 4.1.119.Final Central 2025-02-26
> io.opentelemetry:opentelemetry-api:1.42.1
> ↳ Minor upgrade 1.48.0 Central 2025-03-12
>
> io.opentelemetry.instrumentation:opentelemetry-instrumentation-annotations:2.8.0
> ↳ Minor upgrade 2.14.0 Central 2025-03-19
> io.opentelemetry.semconv:opentelemetry-semconv:1.25.0-alpha
> ↳ Minor upgrade 1.31.0 Central new
> io.perfmark:perfmark-api:0.23.0
> ↳ Minor upgrade 0.27.0 Central 2024-02-07
> io.prometheus:prometheus-metrics-config:1.3.1 1.3.6 Central 2025-03-26
> io.smallrye:smallrye-jwt:4.3.1
> ↳ Minor upgrade 4.6.1 Central 2024-11-20
> io.smallrye:smallrye-open-api-core:4.0.8 4.0.9 Central new
> io.smallrye.common:smallrye-common-annotation:2.10.0
> ↳ Minor upgrade 2.11.0 Central new
> io.smallrye.reactive:mutiny:2.7.0
> ↳ Minor upgrade 2.8.0 Central 2025-01-22
> io.smallrye.reactive:smallrye-mutiny-vertx-amqp-client:3.17.1
> ↳ Minor upgrade 3.18.1 Central 2025-02-12
> io.smallrye.reactive:smallrye-reactive-converter-api:2.6.0
> ↳ Minor upgrade 2.7.0 Central 2024-02-07
> ↳ Very latest 3.0.1 Central 2024-02-07
> io.smallrye.reactive:smallrye-reactive-messaging-amqp:4.25.0
> ↳ Minor upgrade 4.27.0 Central 2025-01-15
> io.vertx:vertx-kafka-client:4.4.9
> ↳ Minor upgrade 4.5.13 Central 2025-02-12
> jakarta.annotation:jakarta.annotation-api:2.1.1
> ↳ Very latest 3.0.0 Central 2024-04-10
> jakarta.enterprise:jakarta.enterprise.cdi-api:2.0.2
> ↳ Very latest 4.1.0 Central 2024-04-17
> jakarta.enterprise:jakarta.enterprise.cdi-api:4.0.1
> ↳ Minor upgrade 4.1.0 Central 2024-04-17
> jakarta.enterprise.concurrent:jakarta.enterprise.concurrent-api:3.0.3
> 3.0.4 Central 2024-07-03
> ↳ Minor upgrade 3.1.1 Central 2024-06-26
> jakarta.faces:jakarta.faces-api:4.0.1
> ↳ Minor upgrade 4.1.2 Central 2024-11-06
> jakarta.inject:jakarta.inject-api:1.0.5
> ↳ Very latest 2.0.1 Central 2024-02-07
> jakarta.persistence:jakarta.persistence-api:3.1.0
> ↳ Minor upgrade 3.2.0 Central 2024-05-22
> jakarta.security.enterprise:jakarta.security.enterprise-api:3.0.0
> ↳ Very latest 4.0.0 Central 2024-06-26
> jakarta.servlet:jakarta.servlet-api:6.0.0
> ↳ Minor upgrade 6.1.0 Central 2024-06-12
> jakarta.servlet.jsp:jakarta.servlet.jsp-api:3.1.1
> ↳ Very latest 4.0.0 Central 2024-06-12
> jakarta.validation:jakarta.validation-api:3.0.2
> ↳ Minor upgrade 3.1.1 Central 2025-02-05
> jakarta.websocket:jakarta.websocket-api:2.1.1
> ↳ Minor upgrade 2.2.0 Central 2024-05-29
> jakarta.ws.rs:jakarta.ws.rs-api:3.1.0
> ↳ Very latest 4.0.0 Central 2024-05-08
> joda-time:joda-time:2.12.7
> ↳ Minor upgrade 2.14.0 Central new
> net.bytebuddy:byte-buddy:1.15.11
> ↳ Minor upgrade 1.17.5 Central new
> net.bytebuddy:byte-buddy:1.15.11
> ↳ Minor upgrade 1.17.5 Central 2025-04-02
> net.shibboleth.utilities:java-support:8.0.0
> ↳ Minor upgrade 8.4.2 JBossPublic 2024-04-17
> org.antlr:antlr4:4.13.0 4.13.2 Central 2024-08-14
> org.apache.cxf:cxf-core:4.0.6 4.0.7 Central 2025-03-12
> ↳ Minor upgrade 4.1.1 Central 2025-03-12
> org.apache.cxf.xjc-utils:cxf-xjc-runtime:4.0.1 4.0.2 Central 2024-08-28
> ↳ Minor upgrade 4.1.0 Central 2024-12-11
> org.apache.kafka:kafka-clients:3.9.0
> ↳ Very latest 4.0.0 Central 2025-03-19
> org.apache.kerby:kerb-server-api-all:2.0.3
> ↳ Minor upgrade 2.1.0 Central 2024-08-14
> org.apache.lucene:lucene-analysis-common:9.11.1
> ↳ Minor upgrade 9.12.1 Central 2024-12-18
> ↳ Very latest 10.1.0 Central 2024-12-25
> org.apache.lucene:lucene-analysis-common:9.12.1
> ↳ Very latest 10.1.0 Central 2024-12-25
> org.apache.santuario:xmlsec:3.0.5
> ↳ Very latest 4.0.3 Central 2024-11-06
> org.apache.velocity:velocity-engine-core:2.3
> ↳ Minor upgrade 2.4.1 Central 2024-10-23
> org.apache.ws.xmlschema:xmlschema-core:2.3.0 2.3.1 Central 2024-02-07
> org.apache.wss4j:wss4j-bindings:3.0.4
> ↳ Very latest 4.0.0 Central 2025-02-19
> org.assertj:assertj-bom:3.26.3
> ↳ Minor upgrade 3.27.3 Central 2025-01-22
> org.cryptacular:cryptacular:1.2.5 1.2.7 Central 2024-08-21
> org.eclipse.jdt:ecj:3.33.0
> ↳ Minor upgrade 3.41.0 Central 2025-03-12
> org.elasticsearch.client:elasticsearch-rest-client:8.15.4 8.15.5 Central
> 2024-11-27
> ↳ Minor upgrade 8.17.4 Central 2025-03-26
> org.glassfish:jakarta.faces:4.0.11
> ↳ Minor upgrade 4.1.3 Central 2025-03-12
> org.glassfish.soteria:soteria.spi.bean.decorator.weld:3.0.3
> ↳ Very latest 4.0.0 Central 2024-08-21
> org.hibernate.orm:hibernate-core:6.6.7.Final 6.6.12.Final Central new
> org.infinispan:infinispan-bom:15.1.7.Final
> ↳ Minor upgrade 15.2.0.Final Central new
> org.jboss.genericjms:generic-jms-ra-jar:3.0.0.Final
> ↳ Minor upgrade 3.1.0 Central 2024-02-07
> org.jboss.hal:hal-console:3.7.9.Final 3.7.10.Final Central new
> org.jboss.metadata:jboss-metadata-appclient:16.0.0.Final
> ↳ Minor upgrade 16.1.0.Final Central 2025-02-05
> org.jboss.weld:weld-api:5.0.SP3
> ↳ Very latest 6.0.Final Central 2024-12-18
> org.jboss.weld:weld-core-impl:5.1.5.Final
> ↳ Very latest 6.0.1.Final Central 2025-02-19
> org.jgroups:jgroups:5.3.16.Final
> ↳ Minor upgrade 5.4.5.Final Central 2025-03-19
> org.junit:junit-bom:5.10.5
> ↳ Minor upgrade 5.12.1 Central 2025-03-19
> org.mockito:mockito-bom:5.14.2
> ↳ Minor upgrade 5.16.1 Central 2025-03-19
> org.opensaml:opensaml-profile-api:4.3.2
> ↳ Very latest 5.1.4 JBossPublic new
> org.ow2.asm:asm:9.7.1
> ↳ Minor upgrade 9.8 Central new
> org.wildfly:wildfly-naming-client:1.0.17.Final
> ↳ Minor upgrade 1.1.0.Final Central 2024-02-07
> ↳ Very latest 2.0.1.Final Central 2024-02-07
> org.xerial.snappy:snappy-java:1.1.10.5 1.1.10.7 Central 2024-09-11
> software.amazon.awssdk:annotations:2.30.32 2.30.38 Central 2025-03-12
> ↳ Minor upgrade 2.31.13 Central new
> 81 items
>
> Generated on 2025-04-02
>
> Report generated by Maven Dependency Updater
> <
https://github.com/jboss-set/maven-dependency-updater>
> _______________________________________________
> wildfly-dev mailing list -- wildfly-dev(a)lists.jboss.org
> To unsubscribe send an email to wildfly-dev-leave(a)lists.jboss.org
> Privacy Statement:
https://www.redhat.com/en/about/privacy-policy
> List Archives:
>
https://lists.jboss.org/archives/list/wildfly-dev@lists.jboss.org/message...
>
--
Brian Stansberry
Principal Architect, Red Hat JBoss EAP
WildFly Project Lead
He/Him/His
--
Brian Stansberry
Principal Architect, Red Hat JBoss EAP
WildFly Project Lead
He/Him/His