mina-sshd icon indicating copy to clipboard operation
mina-sshd copied to clipboard

Bump org.apache.mina:mina-core from 2.0.23 to 2.2.3

Open dependabot[bot] opened this issue 1 year ago • 4 comments

Bumps org.apache.mina:mina-core from 2.0.23 to 2.2.3.

Commits
  • 906884d [maven-release-plugin] prepare release 2.2.3
  • abeddb9 Downgraded the maven source plugin version because 3.3.0 fails
  • 677e729 o Bumped up dependencies and maven polugins
  • 48de5d2 Ignore the test, otherwise it will loop forever
  • 1a7c450 Renamed the DIRMINA1172 test
  • 3e638d1 Merge remote-tracking branch 'origin/2.2.X' into 2.2.X
  • c723045 Fix for DIRMINA-1172
  • 26f6f99 Use the diamond notation
  • 0145d1a Use stock JRE Charset instead of magic string
  • 269aef1 Use stock JRE Charset instead of magic string
  • Additional commits viewable in compare view

Dependabot compatibility score

You can trigger a rebase of this PR by commenting @dependabot rebase.


Dependabot commands and options

You can trigger Dependabot actions by commenting on this PR:

  • @dependabot rebase will rebase this PR
  • @dependabot recreate will recreate this PR, overwriting any edits that have been made to it
  • @dependabot merge will merge this PR after your CI passes on it
  • @dependabot squash and merge will squash and merge this PR after your CI passes on it
  • @dependabot cancel merge will cancel a previously requested merge and block automerging
  • @dependabot reopen will reopen this PR if it is closed
  • @dependabot close will close this PR and stop Dependabot recreating it. You can achieve the same result by closing it manually
  • @dependabot show <dependency name> ignore conditions will show all of the ignore conditions of the specified dependency
  • @dependabot ignore this major version will close this PR and stop Dependabot creating any more for this major version (unless you reopen the PR or upgrade to it yourself)
  • @dependabot ignore this minor version will close this PR and stop Dependabot creating any more for this minor version (unless you reopen the PR or upgrade to it yourself)
  • @dependabot ignore this dependency will close this PR and stop Dependabot creating any more for this dependency (unless you reopen the PR or upgrade to it yourself)

Note Automatic rebases have been disabled on this pull request as it has been open for over 30 days.

dependabot[bot] avatar Jul 29 '24 11:07 dependabot[bot]

Uh... are we ready to abandon the 2.0.x stream of Apache MINA? I know for certain that Gerrit uses the MINA transport back-end with MINA 2.0.25. Jumping to 2.2.3 might incur a lot of testing work.

tomaswolf avatar Sep 10 '24 14:09 tomaswolf

Given that a MINA 2.2.4 is forthcoming, I think the correct way forward here would be

  • Leave our POM at 2.0.25.
  • Change https://github.com/apache/mina/blob/14d876107c60a169f11ec2c3ce3cd9aadcd9b43c/mina-core/src/main/java/org/apache/mina/core/service/IoHandler.java#L124 to a default method (empty). That would re-instate binary compatibility, right?
  • Leave our code unchanged. (I.e., don't add the new override.)
  • Mention in the documentation of sshd-mina that it works with MINA >= 2.0.25 or MINA >= 2.2.4.

tomaswolf avatar Sep 10 '24 14:09 tomaswolf

We can't add the method as it has a FilterEvent parameter, which is a new class introduced in Mina 2.1.0. I don't think there's a way to support both 2.0.x and 2.1.x at the same time.
@elecharny any thoughts ?

gnodet avatar Sep 10 '24 15:09 gnodet

@gnodet: yes, I know. But if Apache MINA makes it a default method, then we don't have to declare it at all, and thus we can at least support 2.0.x and >= 2.2.4 with the same code. Yes, we cannot support 2.0.x and (2.1.x or <=2.2.3) at the same time.

tomaswolf avatar Sep 10 '24 15:09 tomaswolf

A newer version of org.apache.mina:mina-core exists, but since this PR has been edited by someone other than Dependabot I haven't updated it. You'll get a PR for the updated version as normal once this PR is merged.

dependabot[bot] avatar Mar 02 '25 15:03 dependabot[bot]

if Apache MINA makes it a default method, then we don't have to declare it at all, and thus we can at least support 2.0.x and >= 2.2.4 with the same code.

See https://github.com/apache/mina/pull/48.

tomaswolf avatar Mar 02 '25 16:03 tomaswolf

Superseded by #681. Keep the dependency at 2.0.X but also test using 2.2.X. In mina-core 2.2.5, that method will be a default method.

tomaswolf avatar Mar 05 '25 21:03 tomaswolf

OK, I won't notify you again about this release, but will get in touch when a new version is available. If you'd rather skip all updates until the next major or minor version, let me know by commenting @dependabot ignore this major version or @dependabot ignore this minor version. You can also ignore all major, minor, or patch releases for a dependency by adding an ignore condition with the desired update_types to your config file.

If you change your mind, just re-open this PR and I'll resolve any conflicts on it.

dependabot[bot] avatar Mar 05 '25 21:03 dependabot[bot]