Skip to content

deps(deps): bump the maven-minor-patch group across 3 directories with 4 updates - #850

Open
dependabot[bot] wants to merge 1 commit into
developfrom
dependabot/maven/develop/maven-minor-patch-b4e200a2b3
Open

dependabot[bot] wants to merge 1 commit into
developfrom
dependabot/maven/develop/maven-minor-patch-b4e200a2b3

Conversation

@dependabot

@dependabot dependabot Bot commented on behalf of github Oct 5, 2026

Copy link
Copy Markdown
Contributor

Bumps the maven-minor-patch group with 4 updates in the / directory: ch.qos.logback:logback-classic, com.tngtech.archunit:archunit, com.itextpdf:itext-core and org.apache.maven:apache-maven.
Bumps the maven-minor-patch group with 2 updates in the /benchmarks directory: ch.qos.logback:logback-classic and com.itextpdf:itext-core.
Bumps the maven-minor-patch group with 1 update in the /examples directory: ch.qos.logback:logback-classic.

Updates ch.qos.logback:logback-classic from 1.6.4 to 1.6.5

Release notes

Sourced from ch.qos.logback:logback-classic's releases.

Logback 1.6.5

2026-09-30 Release of logback version 1.6.5

• Fixed a vulnerability CVE-2026-104721 closely related to CVE-2026-19880. The fix in version 1.6.3, which strips forward and backward slashes from MDC values, was insufficient. An MDC value could still contain relative path components such as .., variable references such as /, or characters that are special in file name patterns and email addresses. This latest vulnerability was found and reported by François Martin (GitHub: @​martinfrancois, https://github.com/martinfrancois).

MDCBasedDiscriminator, used by SiftingAppender, now rejects MDC values instead of stripping characters from them. An MDC value is rejected if it is empty, if it is longer than 64 characters, if it contains the sequence .., or if it contains any of the following characters: / \ $ { } [ ] ( ) | ? * + % , @. When an MDC value is rejected, the discriminator returns the value of its DefaultValue property. A warning is emitted for each rejected value. These warnings are rate-limited.

• When compression is enabled, TimeBasedRollingPolicy and SizeAndTimeBasedRollingPolicy now also remove old log files that were never compressed, for example because the application was not running at rollover time. Previously, such files were ignored by maxHistory and accumulated indefinitely. This issue was discussed in discussions/1032. See TimeBasedRollingPolicy.

• SimpleInvocationGate, deprecated in version 1.6.3, is now marked for removal. Use FixedIntervalInvocationGate instead.

• A bit-wise identical binary of this version can be reproduced by building from source code at commit d1b829dcdb9fd98511c64401beb1419a9c9384aa associated with the tag v_1.6.5. The release was built using Java "21" 2023-10-17 LTS build 21.0.1.+12-LTS-29 under Linux Debian 11.6.

Commits
  • d1b829d prepare release 1.6.5
  • 065b9b2 enhance protectin against mischievious MDC values in MDCBasedDiscriminator
  • b69beab complete commit in relation to discussion_1032
  • 7266c0b fix intermittently failing SocketAppenderMessageLossTest rest condition
  • a633bb0 fix intermittently failing SocketAppenderMessageLossTest rest condition
  • 2bc5bcc renamed tbrp and eclosingTBRP, other minor changes
  • 2cd8762 fix typo in AGENTS.md
  • 647846c fix errors when running tests under intellij IDEA
  • 1048917 removed ConsoleCharsetPropertyDefiner.java
  • 39b5002 added 'since' and 'forRemoval' attributes to SimpleInvocationGate @​Deprecatio...
  • See full diff in compare view

Updates com.tngtech.archunit:archunit from 1.5.0 to 1.5.1

Release notes

Sourced from com.tngtech.archunit:archunit's releases.

ArchUnit 1.5.1

Bug fixes

Core

Internal Improvements

Commits
  • 6c2d659 prepare release 1.5.1
  • d5ff417 set snapshot version to 1.5.1 in preparation of release
  • aee04c5 Update Gradle Wrapper from 9.7.1 to 9.8.0 (#1727)
  • 73535af Update Gradle Wrapper from 9.7.1 to 9.8.0
  • 058f709 Count caught exception types as type dependencies (#1732) (#1725)
  • fbcc47c Count caught exception types as type dependencies (#1732)
  • e78e136 Bump io.github.ben-manes.versions from 0.63.0 to 0.64.0
  • a0a8aff Bump io.github.ben-manes.versions from 0.62.0 to 0.63.0
  • d30f80d Bump io.github.ben-manes.versions from 0.61.0 to 0.62.0
  • 22c0f6a Bump actions/setup-java from 6.0.0 to 6.0.1
  • Additional commits viewable in compare view

Updates com.itextpdf:itext-core from 9.7.1 to 9.8.0

Release notes

Sourced from com.itextpdf:itext-core's releases.

iText Core/Community 9.8.0

We are pleased to announce the release of iText Core 9.8.0. This release introduces support for vertical text layout and CJK writing modes, radial gradients and SVG mask support, and advanced SVG stroke properties. In addition, we’ve introduced a higher-level transformation API with more user-friendly affine transform capabilities in the Layout module, enhanced footnote navigation, critical security updates across key cryptographic and utility dependencies, and substantial performance and standards-conformance improvements.

Vertical Text Layout & CJK Writing Modes

iText Core 9.8.0 introduces initial support for vertical writing modes in the Layout module, primarily aimed at CJK (Chinese, Japanese, and Korean) layouts. Whilst the implementation is not yet complete, the API has been finalized and supports line breaking, baseline adjustments, right-to-left vertical progression, accessibility tagging, and improved sizing behavior in tables, flex containers, inline blocks, and text renderers.

The current implementation also covers word and character spacing, text alignment, overflow handling, text decorations, and text-rise behavior, with related pdfHTML alignment for CSS vertical writing modes.

Layout, Rotations & Transformations

The Layout module now includes more user-friendly affine transformation capabilities, with simplified API options for Property.TRANSFORM. The release also resolves layout issues affecting rotated table cell sizing, content offsets, rotated page coordinates, and relative image positioning with borders.

Advanced SVG & Graphics Capabilities

This release expands SVG and graphics fidelity with radial gradient support across SVG, Kernel, and Layout, SVG support via PDF soft masks, advanced stroke properties such as stroke-linecap, stroke-linejoin, and stroke-miterlimit, URL-based stroke references with fallbacks, and fixes for nested clip paths with translations.

Coming soon: Markdown to PDF

Related to the SVG improvements, we’ve been working on providing Markdown-to-PDF conversion via GitHub Actions. It isn’t part of this release, but we’ll share more very soon.

Security and Stability

iText Core 9.8.0 includes important security and stability updates across cryptographic, JSON, HTTP, and logging dependencies, including IV generation fixes, Bouncy Castle FIPS, Bouncy Castle standard libraries, Jackson Databind, Apache HttpClient, and Logback. It also improves PDF/A and PDF/UA validation, text extraction performance, circular reference protection, digital signature revision validation, custom font link handling, font resource licensing clarity, and runtime compatibility for GraalVM JDK 24/25 environments.

Pull Requests

We’d like to thank Netliomax25 for their fix to improve CSS ~= attribute selector matching in pdfHTML and styled-xml-parser by properly escaping selector values before pattern matching.

Bug Fixes and Miscellaneous

Beyond the headline features, iText Core 9.8.0 includes a broad set of fixes and maintenance updates focused on performance, standards conformance, document stability, packaging quality, and developer experience.

  • Performance and resource handling: Restored Standard 14 font caching in text extraction to address a performance regression, added circular form XObject protection in canvas processing and cleanup workflows, and optimized conditional logging to avoid unnecessary string formatting when log levels are disabled.

  • PDF/A, PDF/UA, and validation improvements: Improved validation for PDF/A documents with multi-stream page contents and refined glyph validation for substituted glyphs without Unicode mappings.

  • Digital signing and document integrity: Corrected revision counting in digital signature validation to avoid over-counting document processing events and improve validation reliability.

  • Layout and rendering fixes: Fixed issues involving custom font links, relative image positioning with borders, rotated table cell sizing, footnote numbering with footer and page-break handling, and margin handling during relayout.

  • Packaging, runtime compatibility, and documentation: Improved GraalVM JDK 24/25 compatibility, and expanded public API documentation for the io module.

  • Compliance and dependency hygiene: Replaced legacy bundled font resources with clearly licensed equivalents, updated related notice information, and improved GraalVM WebP test stability.

Other Stuff

If you use iText for digital signing, you may be interested in the Digital Signatures Hub which contains a ton of useful resources and examples.

Don’t forget that in addition to the resources on our Knowledge Base, on our GitHub you can find a ton of useful up-to-date samples in the following repos:

... (truncated)

Commits
  • 0f61808 [RELEASE] iText 9.8.0
  • b428ff4 [RELEASE] 9.8.0
  • 65e091c Support text-combine-upright and glyph rotation in vertical text
  • b11c4b2 Add missing copyright headers
  • 8d29e99 Deprecate IVGenerator
  • eefc169 Support text rise and underlining for vertical writing
  • 7f3df86 Move supported properties check to ParagraphRenderer
  • cc5998c Finalize vertical text API
  • f4d5c41 Introduce VerticalParagraph
  • 7e1c088 Enable XMSS PQC tests for graalvm after certificate regeneration
  • Additional commits viewable in compare view

Updates org.apache.maven:apache-maven from 3.9.16 to 3.10.0

Updates ch.qos.logback:logback-classic from 1.6.4 to 1.6.5

Release notes

Sourced from ch.qos.logback:logback-classic's releases.

Logback 1.6.5

2026-09-30 Release of logback version 1.6.5

• Fixed a vulnerability CVE-2026-104721 closely related to CVE-2026-19880. The fix in version 1.6.3, which strips forward and backward slashes from MDC values, was insufficient. An MDC value could still contain relative path components such as .., variable references such as /, or characters that are special in file name patterns and email addresses. This latest vulnerability was found and reported by François Martin (GitHub: @​martinfrancois, https://github.com/martinfrancois).

MDCBasedDiscriminator, used by SiftingAppender, now rejects MDC values instead of stripping characters from them. An MDC value is rejected if it is empty, if it is longer than 64 characters, if it contains the sequence .., or if it contains any of the following characters: / \ $ { } [ ] ( ) | ? * + % , @. When an MDC value is rejected, the discriminator returns the value of its DefaultValue property. A warning is emitted for each rejected value. These warnings are rate-limited.

• When compression is enabled, TimeBasedRollingPolicy and SizeAndTimeBasedRollingPolicy now also remove old log files that were never compressed, for example because the application was not running at rollover time. Previously, such files were ignored by maxHistory and accumulated indefinitely. This issue was discussed in discussions/1032. See TimeBasedRollingPolicy.

• SimpleInvocationGate, deprecated in version 1.6.3, is now marked for removal. Use FixedIntervalInvocationGate instead.

• A bit-wise identical binary of this version can be reproduced by building from source code at commit d1b829dcdb9fd98511c64401beb1419a9c9384aa associated with the tag v_1.6.5. The release was built using Java "21" 2023-10-17 LTS build 21.0.1.+12-LTS-29 under Linux Debian 11.6.

Commits
  • d1b829d prepare release 1.6.5
  • 065b9b2 enhance protectin against mischievious MDC values in MDCBasedDiscriminator
  • b69beab complete commit in relation to discussion_1032
  • 7266c0b fix intermittently failing SocketAppenderMessageLossTest rest condition
  • a633bb0 fix intermittently failing SocketAppenderMessageLossTest rest condition
  • 2bc5bcc renamed tbrp and eclosingTBRP, other minor changes
  • 2cd8762 fix typo in AGENTS.md
  • 647846c fix errors when running tests under intellij IDEA
  • 1048917 removed ConsoleCharsetPropertyDefiner.java
  • 39b5002 added 'since' and 'forRemoval' attributes to SimpleInvocationGate @​Deprecatio...
  • See full diff in compare view

Updates com.itextpdf:itext-core from 9.7.1 to 9.8.0

Release notes

Sourced from com.itextpdf:itext-core's releases.

iText Core/Community 9.8.0

We are pleased to announce the release of iText Core 9.8.0. This release introduces support for vertical text layout and CJK writing modes, radial gradients and SVG mask support, and advanced SVG stroke properties. In addition, we’ve introduced a higher-level transformation API with more user-friendly affine transform capabilities in the Layout module, enhanced footnote navigation, critical security updates across key cryptographic and utility dependencies, and substantial performance and standards-conformance improvements.

Vertical Text Layout & CJK Writing Modes

iText Core 9.8.0 introduces initial support for vertical writing modes in the Layout module, primarily aimed at CJK (Chinese, Japanese, and Korean) layouts. Whilst the implementation is not yet complete, the API has been finalized and supports line breaking, baseline adjustments, right-to-left vertical progression, accessibility tagging, and improved sizing behavior in tables, flex containers, inline blocks, and text renderers.

The current implementation also covers word and character spacing, text alignment, overflow handling, text decorations, and text-rise behavior, with related pdfHTML alignment for CSS vertical writing modes.

Layout, Rotations & Transformations

The Layout module now includes more user-friendly affine transformation capabilities, with simplified API options for Property.TRANSFORM. The release also resolves layout issues affecting rotated table cell sizing, content offsets, rotated page coordinates, and relative image positioning with borders.

Advanced SVG & Graphics Capabilities

This release expands SVG and graphics fidelity with radial gradient support across SVG, Kernel, and Layout, SVG support via PDF soft masks, advanced stroke properties such as stroke-linecap, stroke-linejoin, and stroke-miterlimit, URL-based stroke references with fallbacks, and fixes for nested clip paths with translations.

Coming soon: Markdown to PDF

Related to the SVG improvements, we’ve been working on providing Markdown-to-PDF conversion via GitHub Actions. It isn’t part of this release, but we’ll share more very soon.

Security and Stability

iText Core 9.8.0 includes important security and stability updates across cryptographic, JSON, HTTP, and logging dependencies, including IV generation fixes, Bouncy Castle FIPS, Bouncy Castle standard libraries, Jackson Databind, Apache HttpClient, and Logback. It also improves PDF/A and PDF/UA validation, text extraction performance, circular reference protection, digital signature revision validation, custom font link handling, font resource licensing clarity, and runtime compatibility for GraalVM JDK 24/25 environments.

Pull Requests

We’d like to thank Netliomax25 for their fix to improve CSS ~= attribute selector matching in pdfHTML and styled-xml-parser by properly escaping selector values before pattern matching.

Bug Fixes and Miscellaneous

Beyond the headline features, iText Core 9.8.0 includes a broad set of fixes and maintenance updates focused on performance, standards conformance, document stability, packaging quality, and developer experience.

  • Performance and resource handling: Restored Standard 14 font caching in text extraction to address a performance regression, added circular form XObject protection in canvas processing and cleanup workflows, and optimized conditional logging to avoid unnecessary string formatting when log levels are disabled.

  • PDF/A, PDF/UA, and validation improvements: Improved validation for PDF/A documents with multi-stream page contents and refined glyph validation for substituted glyphs without Unicode mappings.

  • Digital signing and document integrity: Corrected revision counting in digital signature validation to avoid over-counting document processing events and improve validation reliability.

  • Layout and rendering fixes: Fixed issues involving custom font links, relative image positioning with borders, rotated table cell sizing, footnote numbering with footer and page-break handling, and margin handling during relayout.

  • Packaging, runtime compatibility, and documentation: Improved GraalVM JDK 24/25 compatibility, and expanded public API documentation for the io module.

  • Compliance and dependency hygiene: Replaced legacy bundled font resources with clearly licensed equivalents, updated related notice information, and improved GraalVM WebP test stability.

Other Stuff

If you use iText for digital signing, you may be interested in the Digital Signatures Hub which contains a ton of useful resources and examples.

Don’t forget that in addition to the resources on our Knowledge Base, on our GitHub you can find a ton of useful up-to-date samples in the following repos:

... (truncated)

Commits
  • 0f61808 [RELEASE] iText 9.8.0
  • b428ff4 [RELEASE] 9.8.0
  • 65e091c Support text-combine-upright and glyph rotation in vertical text
  • b11c4b2 Add missing copyright headers
  • 8d29e99 Deprecate IVGenerator
  • eefc169 Support text rise and underlining for vertical writing
  • 7f3df86 Move supported properties check to ParagraphRenderer
  • cc5998c Finalize vertical text API
  • f4d5c41 Introduce VerticalParagraph
  • 7e1c088 Enable XMSS PQC tests for graalvm after certificate regeneration
  • Additional commits viewable in compare view

Updates ch.qos.logback:logback-classic from 1.6.4 to 1.6.5

Release notes

Sourced from ch.qos.logback:logback-classic's releases.

Logback 1.6.5

2026-09-30 Release of logback version 1.6.5

• Fixed a vulnerability CVE-2026-104721 closely related to CVE-2026-19880. The fix in version 1.6.3, which strips forward and backward slashes from MDC values, was insufficient. An MDC value could still contain relative path components such as .., variable references such as /, or characters that are special in file name patterns and email addresses. This latest vulnerability was found and reported by François Martin (GitHub: @​martinfrancois, https://github.com/martinfrancois).

MDCBasedDiscriminator, used by SiftingAppender, now rejects MDC values instead of stripping characters from them. An MDC value is rejected if it is empty, if it is longer than 64 characters, if it contains the sequence .., or if it contains any of the following characters: / \ $ { } [ ] ( ) | ? * + % , @. When an MDC value is rejected, the discriminator returns the value of its DefaultValue property. A warning is emitted for each rejected value. These warnings are rate-limited.

• When compression is enabled, TimeBasedRollingPolicy and SizeAndTimeBasedRollingPolicy now also remove old log files that were never compressed, for example because the application was not running at rollover time. Previously, such files were ignored by maxHistory and accumulated indefinitely. This issue was discussed in discussions/1032. See TimeBasedRollingPolicy.

• SimpleInvocationGate, deprecated in version 1.6.3, is now marked for removal. Use FixedIntervalInvocationGate instead.

• A bit-wise identical binary of this version can be reproduced by building from source code at commit d1b829dcdb9fd98511c64401beb1419a9c9384aa associated with the tag v_1.6.5. The release was built using Java "21" 2023-10-17 LTS build 21.0.1.+12-LTS-29 under Linux Debian 11.6.

Commits
  • d1b829d prepare release 1.6.5
  • 065b9b2 enhance protectin against mischievious MDC values in MDCBasedDiscriminator
  • b69beab complete commit in relation to discussion_1032
  • 7266c0b fix intermittently failing SocketAppenderMessageLossTest rest condition
  • a633bb0 fix intermittently failing SocketAppenderMessageLossTest rest condition
  • 2bc5bcc renamed tbrp and eclosingTBRP, other minor changes
  • 2cd8762 fix typo in AGENTS.md
  • 647846c fix errors when running tests under intellij IDEA
  • 1048917 removed ConsoleCharsetPropertyDefiner.java
  • 39b5002 added 'since' and 'forRemoval' attributes to SimpleInvocationGate @​Deprecatio...
  • See full diff in compare view

Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting @dependabot rebase.


Dependabot commands and options

You can trigger Dependabot actions by commenting on this PR:

  • @dependabot rebase will rebase this PR
  • @dependabot recreate will recreate this PR, overwriting any edits that have been made to it
  • @dependabot show <dependency name> ignore conditions will show all of the ignore conditions of the specified dependency
  • @dependabot ignore <dependency name> major version will close this group update PR and stop Dependabot creating any more for the specific dependency's major version (unless you unignore this specific dependency's major version or upgrade to it yourself)
  • @dependabot ignore <dependency name> minor version will close this group update PR and stop Dependabot creating any more for the specific dependency's minor version (unless you unignore this specific dependency's minor version or upgrade to it yourself)
  • @dependabot ignore <dependency name> will close this group update PR and stop Dependabot creating any more for the specific dependency (unless you unignore this specific dependency or upgrade to it yourself)
  • @dependabot unignore <dependency name> will remove all of the ignore conditions of the specified dependency
  • @dependabot unignore <dependency name> <ignore condition> will remove the ignore condition of the specified dependency and ignore conditions

…h 4 updates

Bumps the maven-minor-patch group with 4 updates in the / directory: [ch.qos.logback:logback-classic](https://github.com/qos-ch/logback), [com.tngtech.archunit:archunit](https://github.com/TNG/ArchUnit), [com.itextpdf:itext-core](https://github.com/itext/itext7) and org.apache.maven:apache-maven.
Bumps the maven-minor-patch group with 2 updates in the /benchmarks directory: [ch.qos.logback:logback-classic](https://github.com/qos-ch/logback) and [com.itextpdf:itext-core](https://github.com/itext/itext7).
Bumps the maven-minor-patch group with 1 update in the /examples directory: [ch.qos.logback:logback-classic](https://github.com/qos-ch/logback).


Updates `ch.qos.logback:logback-classic` from 1.6.4 to 1.6.5
- [Release notes](https://github.com/qos-ch/logback/releases)
- [Commits](qos-ch/logback@v_1.6.4...v_1.6.5)

Updates `com.tngtech.archunit:archunit` from 1.5.0 to 1.5.1
- [Release notes](https://github.com/TNG/ArchUnit/releases)
- [Commits](TNG/ArchUnit@v1.5.0...v1.5.1)

Updates `com.itextpdf:itext-core` from 9.7.1 to 9.8.0
- [Release notes](https://github.com/itext/itext7/releases)
- [Commits](itext/itext-java@9.7.1...9.8.0)

Updates `org.apache.maven:apache-maven` from 3.9.16 to 3.10.0

Updates `ch.qos.logback:logback-classic` from 1.6.4 to 1.6.5
- [Release notes](https://github.com/qos-ch/logback/releases)
- [Commits](qos-ch/logback@v_1.6.4...v_1.6.5)

Updates `com.itextpdf:itext-core` from 9.7.1 to 9.8.0
- [Release notes](https://github.com/itext/itext7/releases)
- [Commits](itext/itext-java@9.7.1...9.8.0)

Updates `ch.qos.logback:logback-classic` from 1.6.4 to 1.6.5
- [Release notes](https://github.com/qos-ch/logback/releases)
- [Commits](qos-ch/logback@v_1.6.4...v_1.6.5)

---
updated-dependencies:
- dependency-name: ch.qos.logback:logback-classic
  dependency-version: 1.6.5
  dependency-type: direct:production
  update-type: version-update:semver-patch
  dependency-group: maven-minor-patch
- dependency-name: com.tngtech.archunit:archunit
  dependency-version: 1.5.1
  dependency-type: direct:production
  update-type: version-update:semver-patch
  dependency-group: maven-minor-patch
- dependency-name: com.itextpdf:itext-core
  dependency-version: 9.8.0
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: maven-minor-patch
- dependency-name: org.apache.maven:apache-maven
  dependency-version: 3.10.0
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: maven-minor-patch
- dependency-name: ch.qos.logback:logback-classic
  dependency-version: 1.6.5
  dependency-type: direct:production
  update-type: version-update:semver-patch
  dependency-group: maven-minor-patch
- dependency-name: com.itextpdf:itext-core
  dependency-version: 9.8.0
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: maven-minor-patch
- dependency-name: ch.qos.logback:logback-classic
  dependency-version: 1.6.5
  dependency-type: direct:production
  update-type: version-update:semver-patch
  dependency-group: maven-minor-patch
...

Signed-off-by: dependabot[bot] <support@github.com>
@dependabot dependabot Bot added dependencies Pull requests that update a dependency maven Java/Maven dependency updates labels Oct 5, 2026
@dependabot
dependabot Bot requested a review from DemchaAV as a code owner October 5, 2026 04:44
@dependabot dependabot Bot added dependencies Pull requests that update a dependency maven Java/Maven dependency updates labels Oct 5, 2026

This branch has not been deployed

No deployments
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

dependencies Pull requests that update a dependency maven Java/Maven dependency updates

Projects

None yet

Development

Successfully merging this pull request may close these issues.

0 participants