kelp
kelp copied to clipboard
Bump io.github.classgraph:classgraph from 4.8.78 to 4.8.112 in /core
Bumps io.github.classgraph:classgraph from 4.8.78 to 4.8.112.
Release notes
Sourced from io.github.classgraph:classgraph's releases.
classgraph-4.8.112
- Added a secure version of
DocumentBuilderFactoryandXPATHFactoryto prevent XXE (XML External Entity) attack when readingpom.xmlfile (#539, thanks to@kshitizgfor the pull request!).classgraph-4.8.111
Allow globs when accepting/rejecting specific classes, e.g.
new ClassGraph().acceptClasses("*.*Suffix")(#536, thanks to@cushonfor the request!)classgraph-4.8.110
Add method
AnnotationInfo#getParameterValues(boolean includeDefaultValues)so that defaults don't have to be included (#535, thanks to@zerikvfor requesting).classgraph-4.8.109
Add support for Quarkus 1.13's new classloader. Thanks to
@itmrat01for the code contribution! (#531, #532).classgraph-4.8.108
JDK 11 classfile format compatibility fix (JDK 11 added a constant pool tag, and the classfile can't be read without knowing how long the corresponding constant pool entry is expected to be). (#527, thanks to
@haoyuffor reporting.)classgraph-4.8.107
Fix classloader detection for TomEE JAX-RS endpoints (#515, thanks to
@Restagefor detailed assistance in debugging this weird issue!).classgraph-4.8.106
- Support TomEE classloaders for JAX-RS endpoints (#515, thanks to
@Restagefor the request)- Don't try reading
user.dir(the current directory) unless it's on the classpath, since some security environments can't read the current directory (#520, thanks to@elkmanfor the bug report).classgraph-4.8.105
- Fix potential NPE in verbose logging
- Fix for zipfiles between 2GB and 4GB in size, when a zip entry's start position was past the 2GB point in the file (#514, thanks to
@cwmccannfor the bug report)classgraph-4.8.104
Improved verbose logging to include types of methods and fields.
Added a couple of missing methods to
ClassInfoListfor GraphViz visualization of inter-class dependency graphs.classgraph-4.8.103
Fixed issue with duplication of automatic package roots (e.g.
myjar.jar!/BOOT-INF/classes/BOOT-INF/classes/path/to/resource). (#505, thanks to@michael-simonsfor the bug report and reproducer code.)Also fixed an issue where closing the
InputStreamreturned byResource#open()wasn't marking theResourceas closed (which meant the resource couldn't be opened a second time).classgraph-4.8.102
Further improvements in robustness to invalid type signatures that may be generated by the Scala compiler. (#495, thanks to
@jbracker.)classgraph-4.8.101
Made type signature parsing more robust to errors -- the Scala compiler can generate illegal type signatures. (#495, thanks to
@jbrackerfor the report.)classgraph-4.8.99
- Fixed parsing of type parameters and type variables in Scala (these can contain a
$character in Scala, but you don't see that in Java). (#495, thanks to@jbrackerfor the report and for submitting a minimal testcase.)- Fixed a couple of possible exceptions that could be thrown when parsing type annotations for type descriptors.
classgraph-4.8.98
Fix NPE in
hashCode()andequals()methods ofTypeArgument(#491, thanks to@Tagakovfor the fix!).classgraph-4.8.97
... (truncated)
Commits
b3bddc7[maven-release-plugin] prepare release classgraph-4.8.1125e32b91Source > Cleanup2a5dbf7Update README.md5d8d61dUpdate README.md2531599Merge pull request #539 from kshitizg/latest681362aAdding SecureDocumentBuilderFactory & SecureXPATHFactory to prevent XXE( XML ...71ba4a2[maven-release-plugin] prepare for next development iteration4aeda58[maven-release-plugin] prepare release classgraph-4.8.1112022d94Update JavaDocf191ba9Merge branch 'latest' of https://github.com/classgraph/classgraph into latest- Additional commits viewable in compare view
Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting @dependabot rebase.
Dependabot commands and options
You can trigger Dependabot actions by commenting on this PR:
@dependabot rebasewill rebase this PR@dependabot recreatewill recreate this PR, overwriting any edits that have been made to it@dependabot mergewill merge this PR after your CI passes on it@dependabot squash and mergewill squash and merge this PR after your CI passes on it@dependabot cancel mergewill cancel a previously requested merge and block automerging@dependabot reopenwill reopen this PR if it is closed@dependabot closewill close this PR and stop Dependabot recreating it. You can achieve the same result by closing it manually@dependabot show <dependency name> ignore conditionswill show all of the ignore conditions of the specified dependency@dependabot ignore this major versionwill close this PR and stop Dependabot creating any more for this major version (unless you reopen the PR or upgrade to it yourself)@dependabot ignore this minor versionwill close this PR and stop Dependabot creating any more for this minor version (unless you reopen the PR or upgrade to it yourself)@dependabot ignore this dependencywill close this PR and stop Dependabot creating any more for this dependency (unless you reopen the PR or upgrade to it yourself) You can disable automated security fix PRs for this repo from the Security Alerts page.