Skip to content

Bump org.glassfish.hk2:hk2-locator from 3.1.1 to 4.0.0#749

Open
dependabot[bot] wants to merge 1 commit into
dependenciesfrom
dependabot/maven/dependencies/org.glassfish.hk2-hk2-locator-4.0.0
Open

Bump org.glassfish.hk2:hk2-locator from 3.1.1 to 4.0.0#749
dependabot[bot] wants to merge 1 commit into
dependenciesfrom
dependabot/maven/dependencies/org.glassfish.hk2-hk2-locator-4.0.0

Conversation

@dependabot
Copy link
Copy Markdown
Contributor

@dependabot dependabot Bot commented on behalf of github Mar 25, 2026

Bumps org.glassfish.hk2:hk2-locator from 3.1.1 to 4.0.0.

Release notes

Sourced from org.glassfish.hk2:hk2-locator's releases.

4.0.0

Breaking Changes

  • Minimal requirement is Java 17.
  • HK4.0.0 still should work also with Jakarta 10, but new is Jakarta EE 11 support.

New Features

Bug Fixes

Updates of Dependencies

... (truncated)

Commits
  • 9baa361 [maven-release-plugin] prepare release 4.0.0
  • 3a8d1b3 Removed defaultGoal overrides and updated release plugin configuration
  • 4c87c95 Added more tests, improved appending newline char
  • edee7a7 Upgraded hamcrest, removed implicit dependencies
  • dddb2b8 The main used for testing converted to junit test
  • be295e2 TCK runner integrated to the build
  • effdba5 The finalName is read only
  • 1034586 Fixed build with JDK25+
  • 6b36277 Bump org.glassfish.jaxb:jaxb-runtime from 4.0.6 to 4.0.7
  • e70df79 Removed unusable maven repository reference
  • Additional commits viewable in compare view

Dependabot compatibility score

Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting @dependabot rebase.


Dependabot commands and options

You can trigger Dependabot actions by commenting on this PR:

  • @dependabot rebase will rebase this PR
  • @dependabot recreate will recreate this PR, overwriting any edits that have been made to it
  • @dependabot show <dependency name> ignore conditions will show all of the ignore conditions of the specified dependency
  • @dependabot ignore this major version will close this PR and stop Dependabot creating any more for this major version (unless you reopen the PR or upgrade to it yourself)
  • @dependabot ignore this minor version will close this PR and stop Dependabot creating any more for this minor version (unless you reopen the PR or upgrade to it yourself)
  • @dependabot ignore this dependency will close this PR and stop Dependabot creating any more for this dependency (unless you reopen the PR or upgrade to it yourself)

Bumps [org.glassfish.hk2:hk2-locator](https://github.com/eclipse-ee4j/glassfish-hk2) from 3.1.1 to 4.0.0.
- [Release notes](https://github.com/eclipse-ee4j/glassfish-hk2/releases)
- [Changelog](https://github.com/eclipse-ee4j/glassfish-hk2/blob/master/CHANGELOG)
- [Commits](eclipse-ee4j/glassfish-hk2@3.1.1-RELEASE...4.0.0)

---
updated-dependencies:
- dependency-name: org.glassfish.hk2:hk2-locator
  dependency-version: 4.0.0
  dependency-type: direct:development
  update-type: version-update:semver-major
...

Signed-off-by: dependabot[bot] <support@github.com>
@dependabot dependabot Bot added dependencies Pull requests that update a dependency file java Pull requests that update java code labels Mar 25, 2026
@sonarqubecloud
Copy link
Copy Markdown

Quality Gate Failed Quality Gate failed

Failed conditions
2 Security Hotspots
62.5% Coverage on New Code (required ≥ 80%)

See analysis details on SonarQube Cloud

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

dependencies Pull requests that update a dependency file java Pull requests that update java code

Projects

None yet

Development

Successfully merging this pull request may close these issues.

0 participants