Skip to content

chore(deps): bump the maven-dependencies group across 1 directory with 25 updates#558

Merged
jeastham1993 merged 3 commits intomainfrom
dependabot/maven/src/inventory-service/maven-dependencies-90de731256
Dec 3, 2025
Merged

chore(deps): bump the maven-dependencies group across 1 directory with 25 updates#558
jeastham1993 merged 3 commits intomainfrom
dependabot/maven/src/inventory-service/maven-dependencies-90de731256

Conversation

@dependabot
Copy link
Copy Markdown
Contributor

@dependabot dependabot bot commented on behalf of github Nov 24, 2025

Bumps the maven-dependencies group with 25 updates in the /src/inventory-service directory:

Package From To
io.quarkus.platform:quarkus-bom 3.29.0 3.29.4
io.quarkus.platform:quarkus-maven-plugin 3.29.0 3.29.4
io.vertx:vertx-core 4.5.12 5.0.5
software.amazon.awssdk:aws-crt-client 2.38.1 2.39.2
software.amazon.awssdk:dynamodb 2.38.1 2.39.2
software.amazon.awssdk:sns 2.38.1 2.39.2
software.amazon.awssdk:ssm 2.38.1 2.39.2
software.amazon.awssdk:eventbridge 2.38.1 2.39.2
software.amazon.awssdk:apache-client 2.38.1 2.39.2
io.opentelemetry:opentelemetry-api 1.52.0 1.56.0
com.datadoghq:dd-trace-api 1.49.0 1.56.0
com.datadoghq:dd-trace-ot 1.49.0 1.56.0
com.fasterxml.jackson.core:jackson-databind 2.19.1 2.20.1
com.fasterxml.jackson.core:jackson-core 2.19.0 2.20.1
org.testcontainers:testcontainers 1.21.1 2.0.2
org.glassfish.jersey.core:jersey-client 3.0.5 4.0.0
io.smallrye:jandex-maven-plugin 3.1.8 3.5.2
org.apache.maven.plugins:maven-surefire-plugin 3.5.3 3.5.4
org.apache.maven.plugins:maven-failsafe-plugin 3.5.3 3.5.4
org.codehaus.mojo:versions-maven-plugin 2.10.0 2.20.1
com.amazonaws:aws-lambda-java-events 3.16.0 3.16.1
ch.qos.logback:logback-classic 1.5.18 1.5.21
software.amazon.awssdk:sfn 2.37.3 2.39.2
software.amazon.awscdk:aws-cdk-lib 2.199.0 2.229.0
org.junit.jupiter:junit-jupiter 5.13.0 6.0.1

Updates io.quarkus.platform:quarkus-bom from 3.29.0 to 3.29.4

Commits
  • b9fb0e7 [maven-release-plugin] prepare release 3.29.4
  • fa47046 Merge pull request #1665 from gsmet/quarkus-3.29.4
  • eff2f4b Upgrade to Quarkus 3.29.4
  • 802f793 [maven-release-plugin] prepare for next development iteration
  • 1acad47 [maven-release-plugin] prepare release 3.29.3
  • 3633a21 Merge pull request #1663 from gsmet/quarkus-3.29.3
  • eacdcc1 Upgrade to Quarkus 3.29.3
  • 79dfbc6 [maven-release-plugin] prepare for next development iteration
  • 8823701 [maven-release-plugin] prepare release 3.29.2
  • 6c07614 Merge pull request #1655 from gsmet/quarkus-3.29.2
  • Additional commits viewable in compare view

Updates io.quarkus.platform:quarkus-maven-plugin from 3.29.0 to 3.29.4

Commits
  • b9fb0e7 [maven-release-plugin] prepare release 3.29.4
  • fa47046 Merge pull request #1665 from gsmet/quarkus-3.29.4
  • eff2f4b Upgrade to Quarkus 3.29.4
  • 802f793 [maven-release-plugin] prepare for next development iteration
  • 1acad47 [maven-release-plugin] prepare release 3.29.3
  • 3633a21 Merge pull request #1663 from gsmet/quarkus-3.29.3
  • eacdcc1 Upgrade to Quarkus 3.29.3
  • 79dfbc6 [maven-release-plugin] prepare for next development iteration
  • 8823701 [maven-release-plugin] prepare release 3.29.2
  • 6c07614 Merge pull request #1655 from gsmet/quarkus-3.29.2
  • Additional commits viewable in compare view

Updates io.vertx:vertx-core from 4.5.12 to 5.0.5

Commits
  • cc671ef Releasing 5.0.5
  • 86c8be2 NumberFormatException thrown when creating DNS Client with IPv6 address (#5753)
  • 76606d7 HostAndPortImpl#isDIGIT throws ArrayOtOfboundException (#5752)
  • 15ce13b Fix incorrect padded buffer length method calculation.
  • 671a109 Mitigate HTTP/2 MYR test on CI
  • a108e1d Improve Http1xSendFileTest.testSendFileFailsWhenClientClosesConnection
  • 3483039 Clarify how to terminate an http response in the javadoc (#5737)
  • 66293ec Fix racy FileSystemTest#testFileWithLock test that should perform retries to ...
  • 02bb794 Make proxy pooling test consistent on all versions of Java that we support
  • 88f2c95 Keep references on NetClient in socks proxies to avoid them being collected d...
  • Additional commits viewable in compare view

Updates software.amazon.awssdk:aws-crt-client from 2.38.1 to 2.39.2

Updates software.amazon.awssdk:dynamodb from 2.38.1 to 2.39.2

Updates software.amazon.awssdk:sns from 2.38.1 to 2.39.2

Updates software.amazon.awssdk:ssm from 2.38.1 to 2.39.2

Updates software.amazon.awssdk:eventbridge from 2.38.1 to 2.39.2

Updates software.amazon.awssdk:apache-client from 2.38.1 to 2.39.2

Updates software.amazon.awssdk:dynamodb from 2.38.1 to 2.39.2

Updates software.amazon.awssdk:sns from 2.38.1 to 2.39.2

Updates software.amazon.awssdk:ssm from 2.38.1 to 2.39.2

Updates software.amazon.awssdk:eventbridge from 2.38.1 to 2.39.2

Updates io.opentelemetry:opentelemetry-api from 1.52.0 to 1.56.0

Release notes

Sourced from io.opentelemetry:opentelemetry-api's releases.

Version 1.56.0

API

Incubator

  • Support ExtendedOpenTelemetry in GlobalOpenTelemetry (#7799)

SDK

  • Changes to MeterConfig, LoggerConfig, TracerConfig are guaranteed to be eventually visible (#7706)

Metrics

  • Stabilize ExemplarFilter (#7768)
  • Type specific exemplar reservoirs (#7758)

Extensions

  • SDK incubator: Add incubator ComposableRuleBasedSampler (#7787)
  • SDK incubator: Add incubator ComposableAnnotatingSampler (#7804)
  • SDK incubator: Rename ComposableTraceIdRatioBased to ComposableProbability (#7786)
  • Declarative config: BREAKING Remove component provider generic type (#7606)
  • Declarative config: Add declarative config support for ExemplarFilter (#7769)
  • Declarative config: Fix a few declarative configuration bugs (#7807)

Project tooling

  • Move to oracle bare metal benchmark runner (#7740)
  • Enable Develocity build scans (#7776)
  • Document GPG signing key (#7783)
  • Update build to use java 21 (#7784)
  • Sync repository-settings.md documentation (#7791)
  • Fix gradle deprecation warning (#7780)
  • Small alignments of workflows across the 6 Java repos (#7806)
  • Implement min java version gradle tooling from instrumentation repo (#7801)

🙇 Thank you

This release was possible thanks to the following contributors who shared their brilliant ideas and awesome pull requests:

@​anuraaga @​breedx-splk @​brunobat @​jack-berg @​jkwatson @​laurit @​robsunday @​ThomasVitale @​trask @​yogurtearl

... (truncated)

Changelog

Sourced from io.opentelemetry:opentelemetry-api's changelog.

Version 1.56.0 (2025-11-07)

API

Incubator

  • Support ExtendedOpenTelemetry in GlobalOpenTelemetry (#7799)

SDK

  • Changes to MeterConfig, LoggerConfig, TracerConfig are guaranteed to be eventually visible (#7706)

Metrics

  • Stabilize ExemplarFilter (#7768)
  • Type specific exemplar reservoirs (#7758)

Extensions

  • SDK incubator: Add incubator ComposableRuleBasedSampler (#7787)
  • SDK incubator: Add incubator ComposableAnnotatingSampler (#7804)
  • SDK incubator: Rename ComposableTraceIdRatioBased to ComposableProbability (#7786)
  • Declarative config: BREAKING Remove component provider generic type (#7606)
  • Declarative config: Add declarative config support for ExemplarFilter (#7769)
  • Declarative config: Fix a few declarative configuration bugs (#7807)

Project tooling

  • Move to oracle bare metal benchmark runner (#7740)
  • Enable Develocity build scans (#7776)
  • Document GPG signing key (#7783)
  • Update build to use java 21 (#7784)
  • Sync repository-settings.md documentation (#7791)
  • Fix gradle deprecation warning (#7780)

... (truncated)

Commits
  • daa49ee [release/v1.56.x] Prepare release 1.56.0 (#7823)
  • e27f06d Prepare 1.56.0 (#7817)
  • de48d1b Remove component provider generic type (#7606)
  • 408f2d8 Add incubator ComposableAnnotatingSampler (#7804)
  • 578f82b fix(deps): update dependency com.uber.nullaway:nullaway to v0.12.12 (#7811)
  • b10d711 fix(deps): update dependency com.google.api.grpc:proto-google-common-protos t...
  • 1c8db7d chore(deps): update otel/opentelemetry-collector-contrib docker tag to v0.139...
  • 36ca9b8 support ExtendedOpenTelemetry in GlobalOpenTelemetry (#7799)
  • 16af749 chore(deps): update weekly update (#7808)
  • 3ed2bdb Fix a few declarative configuration bugs (#7807)
  • Additional commits viewable in compare view

Updates com.datadoghq:dd-trace-api from 1.49.0 to 1.56.0

Release notes

Sourced from com.datadoghq:dd-trace-api's releases.

1.56.0

Components

Application Security Management (WAF)

Build & Tooling

Configuration

Continuous Integration Visibility

Crash tracking

Data Streams Monitoring

Database Monitoring

  • ✨⚡ Migrate JDBC instrumentation to singleSpanBuilder (#9927 - @​dougqh)
  • 🐛 Fix JDBC's SQLCommenter not taking into account semicolons (#9915 - @​na-ji)

Dynamic Instrumentation

ML Observability (LLMObs)

Metrics

  • 🐛 Fix npe on ConflatingMetricsAggregator when the resource is null (#9909 - @​amarziali)

OpenFeature

... (truncated)

Commits
  • c05874d Add more information for timeout messages (#9999)
  • 0614d73 fix(openfeature): Fix Java version requirements for tests (#10003)
  • 4842f7f Add the tags returned by the service to the ai_guard span (#9931)
  • 8aa326f Implementation of the open feature SDK in the java tracer (#9885)
  • cd631ee Upgrade byte-buddy to latest 1.18.1 (#9997)
  • b3d2c4a DSMON-1141: Track schema registry usage (#9974)
  • 5adec51 Make test span serialization idempotent (#9456)
  • f4668ed Fixed right bound for scala-library to correctly update latest dependencies...
  • 0f63e5e mark flaky Exception Replay integration test (#9970)
  • afc1296 buildSpan -> singleSpanBuilder (#9995)
  • Additional commits viewable in compare view

Updates com.datadoghq:dd-trace-ot from 1.49.0 to 1.56.0

Release notes

Sourced from com.datadoghq:dd-trace-ot's releases.

1.56.0

Components

Application Security Management (WAF)

Build & Tooling

Configuration

Continuous Integration Visibility

Crash tracking

Data Streams Monitoring

Database Monitoring

  • ✨⚡ Migrate JDBC instrumentation to singleSpanBuilder (#9927 - @​dougqh)
  • 🐛 Fix JDBC's SQLCommenter not taking into account semicolons (#9915 - @​na-ji)

Dynamic Instrumentation

ML Observability (LLMObs)

Metrics

  • 🐛 Fix npe on ConflatingMetricsAggregator when the resource is null (#9909 - @​amarziali)

OpenFeature

... (truncated)

Commits
  • c05874d Add more information for timeout messages (#9999)
  • 0614d73 fix(openfeature): Fix Java version requirements for tests (#10003)
  • 4842f7f Add the tags returned by the service to the ai_guard span (#9931)
  • 8aa326f Implementation of the open feature SDK in the java tracer (#9885)
  • cd631ee Upgrade byte-buddy to latest 1.18.1 (#9997)
  • b3d2c4a DSMON-1141: Track schema registry usage (#9974)
  • 5adec51 Make test span serialization idempotent (#9456)
  • f4668ed Fixed right bound for scala-library to correctly update latest dependencies...
  • 0f63e5e mark flaky Exception Replay integration test (#9970)
  • afc1296 buildSpan -> singleSpanBuilder (#9995)
  • Additional commits viewable in compare view

Updates com.fasterxml.jackson.core:jackson-databind from 2.19.1 to 2.20.1

Commits

Updates com.fasterxml.jackson.core:jackson-core from 2.19.0 to 2.20.1

Commits
  • 440a470 [maven-release-plugin] prepare release jackson-core-2.20.1
  • 8bb7c4e Prep for 2.20.1 release
  • 25f77be Merge branch '2.19' into 2.20
  • d7e3877 Post-release dep version bump
  • 11b4ac9 [maven-release-plugin] prepare for next development iteration
  • 8836225 [maven-release-plugin] prepare release jackson-core-2.19.4
  • 68e64f7 Prep for 2.19.4 release
  • 6e81a4f Merge branch '2.19' into 2.20
  • bad4b9b Post-release dep version bump
  • 35ecb54 [maven-release-plugin] prepare for next development iteration
  • Additional commits viewable in compare view

Updates org.testcontainers:testcontainers from 1.21.1 to 2.0.2

Release notes

Sourced from org.testcontainers:testcontainers's releases.

2.0.2

What's Changed

🐛 Bug Fixes

📖 Documentation

🧹 Housekeeping

  • Add getBaseUrl() to NginxContainer using NGINX_DEFAULT_PORT (#11137) @​ghusta

📦 Dependency updates

2.0.1

What's Changed

🐛 Bug Fixes

  • Add MySQLR2DBCDatabaseContainer compatible with org.testcontainers.mysql.MySQLContainer (#11119) @​eddumelendez
  • Add MariaDBR2DBCDatabaseContainer compatible with org.testcontainers.mariadb.MariaDBContainer (#11117) @​eddumelendez
  • Add MSSQLR2DBCDatabaseContainer compatible with org.testcontainers.mssqlserver.MSSQLServerContainer (#11118) @​eddumelendez
  • Add PostgreSQLR2DBCDatabaseContainer compatible with org.testcontainers.postgresql.PostgreSQLContainer (#11120) @​eddumelendez

📖 Documentation

🧹 Housekeeping

2.0.0

Testcontainers 2.0.0

... (truncated)

Commits

Updates software.amazon.awssdk:apache-client from 2.38.1 to 2.39.2

Updates org.glassfish.jersey.core:jersey-client from 3.0.5 to 4.0.0

Updates io.smallrye:jandex-maven-plugin from 3.1.8 to 3.5.2

Release notes

Sourced from io.smallrye:jandex-maven-plugin's releases.

3.5.2

What's Changed

Full Changelog: smallrye/jandex@3.5.1...3.5.2

3.5.1

What's Changed

Full Changelog: smallrye/jandex@3.5.0...3.5.1

3.5.0

  • #575 Jandex2Gizmo#classDescOf() should use the ClassDesc cache
  • #574 Annotations in Method hashCode?
  • #568 Reproducible Jandex indexes
  • #561 Should we move ArC Methods.MethodKey into Jandex?
  • #560 Should we cache ArrayType#name() result for the usual suspects?

3.4.0

  • #543 fix type annotations on the outermost annotatable type of a nested type
  • #544 Gizmo 2 integration

3.3.2

  • #529 fix comment in ClassInfo.simpleName()
  • #538 expose the implicit Object bound in the TypeVariable public API
  • #540 intern EquivalenceKeys for primitive types and class types of java.*

3.3.1

  • #526 ClassInfo#simpleName() behaves inconsistently for nested/top-level classes with a dollar sign in name
  • #519 Add IndexView deprecated javadoc notices
  • #514 add module-info.class

... (truncated)

Commits
  • 14e570f [maven-release-plugin] prepare release 3.5.2
  • fd6350e Amendments before release
  • 593de1b release 3.5.2
  • ad0594a bump Groovy to support JDK 26-ea
  • 8b7c2c5 fix AnnotationOverlayTest on JDK 26-ea
  • 503de03 CI: remove Java 24, add Java 25 and 26-ea
  • ced7298 improve AnnotationInstance binary search
  • 1e4eda4 Bump net.bytebuddy:byte-buddy from 1.17.8 to 1.18.0
  • 83b7038 add DotName.startsWith()
  • 4b0b224 Support lookup of method based on an example method
  • Additional commits viewable in compare view

Updates io.quarkus.platform:quarkus-maven-plugin from 3.29.0 to 3.29.4

Commits
  • b9fb0e7 [maven-release-plugin] prepare release 3.29.4
  • fa47046 Merge pull request #1665 from gsmet/quarkus-3.29.4
  • eff2f4b Upgrade to Quarkus 3.29.4
  • 802f793 [maven-release-plugin] prepare for next development iteration
  • 1acad47 [maven-release-plugin] prepare release 3.29.3
  • 3633a21 Merge pull request #1663 from gsmet/quarkus-3.29.3
  • eacdcc1 Upgrade to Quarkus 3.29.3
  • 79dfbc6 [maven-release-plugin] prepare for next development iteration
  • 8823701 [maven-release-plugin] prepare release 3.29.2
  • 6c07614 Merge pull request #1655 from gsmet/quarkus-3.29.2
  • Additional commits viewable in compare view

Updates org.apache.maven.plugins:maven-surefire-plugin from 3.5.3 to 3.5.4

Release notes

Sourced from org.apache.maven.plugins:maven-surefire-plugin's releases.

3.5.4

🚀 New features and improvements

🐛 Bug Fixes

👻 Maintenance

📦 Dependency updates

Commits
  • 88513d8 [maven-release-plugin] prepare release surefire-3.5.4
  • 9c48828 Simplify cuncumber IT configuration and make windows build working again (#3174)
  • 74b2d8c Bump org.htmlunit:htmlunit from 4.15.0 to 4.16.0 (#3173)
  • 6c30bf1 [SUREFIRE-2298] fix xml output with junit 5 nested classes (#828)
  • 9f49866 Bump org.codehaus.plexus:plexus-i18n from 1.0-beta-10 to 1.0.0 (#3172)
  • fb96954 Bump org.htmlunit:htmlunit from 4.13.0 to 4.15.0 (#3171)
  • 1e63159 Name the shutdown hook (#3170)
  • 76e806a feat: enable prevent branch protection rules (#3168)
  • 0fbfb27 Implement fail-fast behavior for JUnit Platform provider (#3155)
  • 98d081e Bump org.assertj:assertj-core from 3.27.3 to 3.27.4 (#3167)
  • Additional commits viewable in compare view

Updates org.apache.maven.plugins:maven-failsafe-plugin from 3.5.3 to 3.5.4

Release notes

Sourced from org.apache.maven.plugins:maven-failsafe-plugin's releases.

3.5.4

🚀 New features and improvements

🐛 Bug Fixes

👻 Maintenance

…h 25 updates

Bumps the maven-dependencies group with 25 updates in the /src/inventory-service directory:

| Package | From | To |
| --- | --- | --- |
| [io.quarkus.platform:quarkus-bom](https://github.com/quarkusio/quarkus-platform) | `3.29.0` | `3.29.4` |
| [io.quarkus.platform:quarkus-maven-plugin](https://github.com/quarkusio/quarkus-platform) | `3.29.0` | `3.29.4` |
| [io.vertx:vertx-core](https://github.com/eclipse/vert.x) | `4.5.12` | `5.0.5` |
| software.amazon.awssdk:aws-crt-client | `2.38.1` | `2.39.2` |
| software.amazon.awssdk:dynamodb | `2.38.1` | `2.39.2` |
| software.amazon.awssdk:sns | `2.38.1` | `2.39.2` |
| software.amazon.awssdk:ssm | `2.38.1` | `2.39.2` |
| software.amazon.awssdk:eventbridge | `2.38.1` | `2.39.2` |
| software.amazon.awssdk:apache-client | `2.38.1` | `2.39.2` |
| [io.opentelemetry:opentelemetry-api](https://github.com/open-telemetry/opentelemetry-java) | `1.52.0` | `1.56.0` |
| [com.datadoghq:dd-trace-api](https://github.com/datadog/dd-trace-java) | `1.49.0` | `1.56.0` |
| [com.datadoghq:dd-trace-ot](https://github.com/datadog/dd-trace-java) | `1.49.0` | `1.56.0` |
| [com.fasterxml.jackson.core:jackson-databind](https://github.com/FasterXML/jackson) | `2.19.1` | `2.20.1` |
| [com.fasterxml.jackson.core:jackson-core](https://github.com/FasterXML/jackson-core) | `2.19.0` | `2.20.1` |
| [org.testcontainers:testcontainers](https://github.com/testcontainers/testcontainers-java) | `1.21.1` | `2.0.2` |
| org.glassfish.jersey.core:jersey-client | `3.0.5` | `4.0.0` |
| [io.smallrye:jandex-maven-plugin](https://github.com/smallrye/jandex) | `3.1.8` | `3.5.2` |
| [org.apache.maven.plugins:maven-surefire-plugin](https://github.com/apache/maven-surefire) | `3.5.3` | `3.5.4` |
| [org.apache.maven.plugins:maven-failsafe-plugin](https://github.com/apache/maven-surefire) | `3.5.3` | `3.5.4` |
| [org.codehaus.mojo:versions-maven-plugin](https://github.com/mojohaus/versions) | `2.10.0` | `2.20.1` |
| [com.amazonaws:aws-lambda-java-events](https://github.com/aws/aws-lambda-java-libs) | `3.16.0` | `3.16.1` |
| [ch.qos.logback:logback-classic](https://github.com/qos-ch/logback) | `1.5.18` | `1.5.21` |
| software.amazon.awssdk:sfn | `2.37.3` | `2.39.2` |
| [software.amazon.awscdk:aws-cdk-lib](https://github.com/aws/aws-cdk) | `2.199.0` | `2.229.0` |
| [org.junit.jupiter:junit-jupiter](https://github.com/junit-team/junit-framework) | `5.13.0` | `6.0.1` |



Updates `io.quarkus.platform:quarkus-bom` from 3.29.0 to 3.29.4
- [Commits](quarkusio/quarkus-platform@3.29.0...3.29.4)

Updates `io.quarkus.platform:quarkus-maven-plugin` from 3.29.0 to 3.29.4
- [Commits](quarkusio/quarkus-platform@3.29.0...3.29.4)

Updates `io.vertx:vertx-core` from 4.5.12 to 5.0.5
- [Commits](eclipse-vertx/vert.x@4.5.12...5.0.5)

Updates `software.amazon.awssdk:aws-crt-client` from 2.38.1 to 2.39.2

Updates `software.amazon.awssdk:dynamodb` from 2.38.1 to 2.39.2

Updates `software.amazon.awssdk:sns` from 2.38.1 to 2.39.2

Updates `software.amazon.awssdk:ssm` from 2.38.1 to 2.39.2

Updates `software.amazon.awssdk:eventbridge` from 2.38.1 to 2.39.2

Updates `software.amazon.awssdk:apache-client` from 2.38.1 to 2.39.2

Updates `software.amazon.awssdk:dynamodb` from 2.38.1 to 2.39.2

Updates `software.amazon.awssdk:sns` from 2.38.1 to 2.39.2

Updates `software.amazon.awssdk:ssm` from 2.38.1 to 2.39.2

Updates `software.amazon.awssdk:eventbridge` from 2.38.1 to 2.39.2

Updates `io.opentelemetry:opentelemetry-api` from 1.52.0 to 1.56.0
- [Release notes](https://github.com/open-telemetry/opentelemetry-java/releases)
- [Changelog](https://github.com/open-telemetry/opentelemetry-java/blob/main/CHANGELOG.md)
- [Commits](open-telemetry/opentelemetry-java@v1.52.0...v1.56.0)

Updates `com.datadoghq:dd-trace-api` from 1.49.0 to 1.56.0
- [Release notes](https://github.com/datadog/dd-trace-java/releases)
- [Changelog](https://github.com/DataDog/dd-trace-java/blob/master/docs/releases.md)
- [Commits](DataDog/dd-trace-java@v1.49.0...v1.56.0)

Updates `com.datadoghq:dd-trace-ot` from 1.49.0 to 1.56.0
- [Release notes](https://github.com/datadog/dd-trace-java/releases)
- [Changelog](https://github.com/DataDog/dd-trace-java/blob/master/docs/releases.md)
- [Commits](DataDog/dd-trace-java@v1.49.0...v1.56.0)

Updates `com.fasterxml.jackson.core:jackson-databind` from 2.19.1 to 2.20.1
- [Commits](https://github.com/FasterXML/jackson/commits)

Updates `com.fasterxml.jackson.core:jackson-core` from 2.19.0 to 2.20.1
- [Commits](FasterXML/jackson-core@jackson-core-2.19.0...jackson-core-2.20.1)

Updates `org.testcontainers:testcontainers` from 1.21.1 to 2.0.2
- [Release notes](https://github.com/testcontainers/testcontainers-java/releases)
- [Changelog](https://github.com/testcontainers/testcontainers-java/blob/main/CHANGELOG.md)
- [Commits](testcontainers/testcontainers-java@1.21.1...2.0.2)

Updates `software.amazon.awssdk:apache-client` from 2.38.1 to 2.39.2

Updates `org.glassfish.jersey.core:jersey-client` from 3.0.5 to 4.0.0

Updates `io.smallrye:jandex-maven-plugin` from 3.1.8 to 3.5.2
- [Release notes](https://github.com/smallrye/jandex/releases)
- [Changelog](https://github.com/smallrye/jandex/blob/main/RELEASE_PROCEDURE.md)
- [Commits](smallrye/jandex@3.1.8...3.5.2)

Updates `io.quarkus.platform:quarkus-maven-plugin` from 3.29.0 to 3.29.4
- [Commits](quarkusio/quarkus-platform@3.29.0...3.29.4)

Updates `org.apache.maven.plugins:maven-surefire-plugin` from 3.5.3 to 3.5.4
- [Release notes](https://github.com/apache/maven-surefire/releases)
- [Commits](apache/maven-surefire@surefire-3.5.3...surefire-3.5.4)

Updates `org.apache.maven.plugins:maven-failsafe-plugin` from 3.5.3 to 3.5.4
- [Release notes](https://github.com/apache/maven-surefire/releases)
- [Commits](apache/maven-surefire@surefire-3.5.3...surefire-3.5.4)

Updates `org.apache.maven.plugins:maven-failsafe-plugin` from 3.5.3 to 3.5.4
- [Release notes](https://github.com/apache/maven-surefire/releases)
- [Commits](apache/maven-surefire@surefire-3.5.3...surefire-3.5.4)

Updates `org.codehaus.mojo:versions-maven-plugin` from 2.10.0 to 2.20.1
- [Release notes](https://github.com/mojohaus/versions/releases)
- [Changelog](https://github.com/mojohaus/versions/blob/master/ReleaseNotes.md)
- [Commits](mojohaus/versions@versions-maven-plugin-2.10.0...2.20.1)

Updates `com.amazonaws:aws-lambda-java-events` from 3.16.0 to 3.16.1
- [Commits](https://github.com/aws/aws-lambda-java-libs/commits)

Updates `ch.qos.logback:logback-classic` from 1.5.18 to 1.5.21
- [Release notes](https://github.com/qos-ch/logback/releases)
- [Commits](qos-ch/logback@v_1.5.18...v_1.5.21)

Updates `software.amazon.awssdk:sfn` from 2.37.3 to 2.39.2

Updates `software.amazon.awscdk:aws-cdk-lib` from 2.199.0 to 2.229.0
- [Release notes](https://github.com/aws/aws-cdk/releases)
- [Changelog](https://github.com/aws/aws-cdk/blob/main/CHANGELOG.v2.alpha.md)
- [Commits](aws/aws-cdk@v2.199.0...v2.229.0)

Updates `org.junit.jupiter:junit-jupiter` from 5.13.0 to 6.0.1
- [Release notes](https://github.com/junit-team/junit-framework/releases)
- [Commits](junit-team/junit-framework@r5.13.0...r6.0.1)

---
updated-dependencies:
- dependency-name: io.quarkus.platform:quarkus-bom
  dependency-version: 3.29.4
  dependency-type: direct:production
  update-type: version-update:semver-patch
  dependency-group: maven-dependencies
- dependency-name: io.quarkus.platform:quarkus-maven-plugin
  dependency-version: 3.29.4
  dependency-type: direct:production
  update-type: version-update:semver-patch
  dependency-group: maven-dependencies
- dependency-name: io.vertx:vertx-core
  dependency-version: 5.0.5
  dependency-type: direct:production
  update-type: version-update:semver-major
  dependency-group: maven-dependencies
- dependency-name: software.amazon.awssdk:aws-crt-client
  dependency-version: 2.39.2
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: maven-dependencies
- dependency-name: software.amazon.awssdk:dynamodb
  dependency-version: 2.39.2
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: maven-dependencies
- dependency-name: software.amazon.awssdk:sns
  dependency-version: 2.39.2
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: maven-dependencies
- dependency-name: software.amazon.awssdk:ssm
  dependency-version: 2.39.2
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: maven-dependencies
- dependency-name: software.amazon.awssdk:eventbridge
  dependency-version: 2.39.2
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: maven-dependencies
- dependency-name: software.amazon.awssdk:apache-client
  dependency-version: 2.39.2
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: maven-dependencies
- dependency-name: software.amazon.awssdk:dynamodb
  dependency-version: 2.39.2
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: maven-dependencies
- dependency-name: software.amazon.awssdk:sns
  dependency-version: 2.39.2
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: maven-dependencies
- dependency-name: software.amazon.awssdk:ssm
  dependency-version: 2.39.2
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: maven-dependencies
- dependency-name: software.amazon.awssdk:eventbridge
  dependency-version: 2.39.2
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: maven-dependencies
- dependency-name: io.opentelemetry:opentelemetry-api
  dependency-version: 1.56.0
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: maven-dependencies
- dependency-name: com.datadoghq:dd-trace-api
  dependency-version: 1.56.0
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: maven-dependencies
- dependency-name: com.datadoghq:dd-trace-ot
  dependency-version: 1.56.0
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: maven-dependencies
- dependency-name: com.fasterxml.jackson.core:jackson-databind
  dependency-version: 2.20.1
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: maven-dependencies
- dependency-name: com.fasterxml.jackson.core:jackson-core
  dependency-version: 2.20.1
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: maven-dependencies
- dependency-name: org.testcontainers:testcontainers
  dependency-version: 2.0.2
  dependency-type: direct:production
  update-type: version-update:semver-major
  dependency-group: maven-dependencies
- dependency-name: software.amazon.awssdk:apache-client
  dependency-version: 2.39.2
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: maven-dependencies
- dependency-name: org.glassfish.jersey.core:jersey-client
  dependency-version: 4.0.0
  dependency-type: direct:production
  update-type: version-update:semver-major
  dependency-group: maven-dependencies
- dependency-name: io.smallrye:jandex-maven-plugin
  dependency-version: 3.5.2
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: maven-dependencies
- dependency-name: io.quarkus.platform:quarkus-maven-plugin
  dependency-version: 3.29.4
  dependency-type: direct:production
  update-type: version-update:semver-patch
  dependency-group: maven-dependencies
- dependency-name: org.apache.maven.plugins:maven-surefire-plugin
  dependency-version: 3.5.4
  dependency-type: direct:production
  update-type: version-update:semver-patch
  dependency-group: maven-dependencies
- dependency-name: org.apache.maven.plugins:maven-failsafe-plugin
  dependency-version: 3.5.4
  dependency-type: direct:production
  update-type: version-update:semver-patch
  dependency-group: maven-dependencies
- dependency-name: org.apache.maven.plugins:maven-failsafe-plugin
  dependency-version: 3.5.4
  dependency-type: direct:production
  update-type: version-update:semver-patch
  dependency-group: maven-dependencies
- dependency-name: org.codehaus.mojo:versions-maven-plugin
  dependency-version: 2.20.1
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: maven-dependencies
- dependency-name: com.amazonaws:aws-lambda-java-events
  dependency-version: 3.16.1
  dependency-type: direct:production
  update-type: version-update:semver-patch
  dependency-group: maven-dependencies
- dependency-name: ch.qos.logback:logback-classic
  dependency-version: 1.5.21
  dependency-type: direct:production
  update-type: version-update:semver-patch
  dependency-group: maven-dependencies
- dependency-name: software.amazon.awssdk:sfn
  dependency-version: 2.39.2
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: maven-dependencies
- dependency-name: software.amazon.awscdk:aws-cdk-lib
  dependency-version: 2.229.0
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: maven-dependencies
- dependency-name: org.junit.jupiter:junit-jupiter
  dependency-version: 6.0.1
  dependency-type: direct:development
  update-type: version-update:semver-major
  dependency-group: maven-dependencies
...

Signed-off-by: dependabot[bot] <support@github.com>
@dependabot dependabot bot added dependencies Pull requests that update a dependency file java labels Nov 24, 2025
@dependabot dependabot bot requested a review from jeastham1993 as a code owner November 24, 2025 22:49
@dependabot dependabot bot added java dependencies Pull requests that update a dependency file labels Nov 24, 2025
@claude
Copy link
Copy Markdown

claude bot commented Dec 3, 2025

Claude finished @dependabot[bot]'s task —— View job


PR Review: Maven Dependencies Update

Review Checklist

  • Read and analyze all changed files
  • Check major version upgrades for breaking changes
  • Review security implications
  • Assess performance considerations
  • Evaluate test coverage impact
  • Provide comprehensive feedback

⚠️ Critical Issues Found

Major Version Upgrades Requiring Immediate Attention

1. JUnit Jupiter 5.13.0 → 6.0.1 (MAJOR BREAKING CHANGE)

  • Files: src/inventory-service/cdk/pom.xml:20
  • CRITICAL: JUnit 6.0.1 introduces significant breaking changes from JUnit 5
  • Risk: Tests may fail to compile or run due to API changes
  • Action Required: Thorough testing and potential code updates needed

2. Vert.x 4.5.12 → 5.0.5 (MAJOR BREAKING CHANGE)

  • REMOVED: The io.vertx:vertx-core dependency was completely removed from inventory-api and inventory-core POMs
  • Risk: If any code directly uses Vert.x APIs, this will cause compilation failures
  • Good Practice: Removal suggests migration to Quarkus abstractions

3. Testcontainers 1.21.1 → 2.0.2 (MAJOR BREAKING CHANGE)

  • Files: Multiple POM files
  • Risk: API changes in major version upgrade
  • Note: Version inconsistency found - testcontainers:junit-jupiter remains at 1.21.3

4. Java Runtime Upgrade 21 → 25

  • Files: Multiple infrastructure configurations, Dockerfiles, GitHub Actions
  • Risk: Java 25 is very new and may have compatibility issues
  • Concern: Production stability with bleeding-edge JVM

🐛 Bugs and Issues

Version Inconsistencies

  1. Testcontainers version mismatch:

    • testcontainers:testcontainers → 2.0.2
    • testcontainers:junit-jupiter → 1.21.3 (not updated)
    • Impact: Potential compatibility issues between different Testcontainers modules
  2. Jackson version inconsistency:

    • jackson-databind and jackson-core → 2.20.1
    • jackson-annotations → 2.20 (missing patch version)
    • Impact: Minor, but could cause subtle serialization issues

Potential Compilation Issues

  1. Jersey Client 3.0.5 → 4.0.0 (MAJOR)
    • File: src/inventory-service/inventory-core/pom.xml:140
    • Risk: Breaking API changes in major version
    • Needs: Code review for JAX-RS client usage

🔒 Security Considerations

Positive Security Updates

Datadog Trace Libraries: Updated to 1.56.0 - includes security fixes
OpenTelemetry: Updated to 1.56.0 - latest security patches
Logback: Updated to 1.5.21 - security improvements
AWS SDK: Updated to 2.39.2 - latest security patches

Infrastructure Security

Datadog Lambda Extension: Updated from v85 → v90

  • Files: CDK, Terraform, SAM template
  • Impact: Latest monitoring capabilities and security fixes

⚡ Performance Considerations

Potential Performance Impact

  1. Java 25 Runtime:

    • Pros: Latest JVM optimizations and garbage collection improvements
    • Cons: Unproven in production environments, potential stability issues
  2. Major Library Updates:

    • JUnit 6.0.1 may have different performance characteristics
    • Testcontainers 2.0.2 includes performance optimizations

🧪 Test Coverage Impact

HIGH RISK - Testing Framework Changes

  1. JUnit 6.0.1 Upgrade:

    • Breaking Changes: API modifications from JUnit 5
    • Action Required: All test classes need review and potential updates
    • Files Affected: All test modules in the inventory service
  2. Testcontainers 2.0.2:

    • API Changes: Major version upgrade may require test updates
    • Docker Compatibility: Updated to support latest Docker versions

📋 Recommendations

IMMEDIATE ACTION REQUIRED

  1. 🚨 BEFORE MERGE: Run full test suite to verify JUnit 6.0.1 compatibility
  2. 🚨 BEFORE MERGE: Test Testcontainers integration tests
  3. 🚨 BEFORE MERGE: Verify Jersey client functionality still works

Version Fixes Needed

  1. Update testcontainers:junit-jupiter to 2.0.2 for consistency
  2. Update jackson-annotations to 2.20.1 to match other Jackson libs

Infrastructure Validation

  1. Test Java 25 compatibility in staging environment first
  2. Monitor Lambda cold starts with new runtime
  3. Validate CDK deployment with AWS CDK 2.229.0

Code Quality Recommendations

Good Practice: Removed direct Vert.x dependency, showing proper abstraction usage
Good Practice: Consistent AWS SDK version management with ${aws.sdk.version}
Good Practice: Updated build tools (Maven Surefire, Jandex plugin)

🎯 Summary

Overall Assessment: ⚠️ HIGH RISK - Multiple major version upgrades require careful testing

Key Concerns:

  • JUnit 6.0.1 upgrade likely to break existing tests
  • Java 25 runtime is bleeding-edge for production
  • Version inconsistencies need resolution

Recommended Actions:

  1. Run comprehensive test suite before merge
  2. Fix version inconsistencies
  3. Consider staging the Java runtime upgrade separately
  4. Have rollback plan ready

@jeastham1993 jeastham1993 merged commit e2b7839 into main Dec 3, 2025
13 checks passed
@dependabot dependabot bot deleted the dependabot/maven/src/inventory-service/maven-dependencies-90de731256 branch December 3, 2025 12:11
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

dependencies Pull requests that update a dependency file java

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant