chore(deps, amber): update sbt patch updates - #7264
Conversation
Automated Reviewer SuggestionsBased on the
|
❌ 1 Tests Failed:
View the top 1 failed test(s) by shortest run time
To view more test analytics, go to the Test Analytics Dashboard |
|
| config | throughput | MB/s | latency | max Δ latest / 7d | |
|---|---|---|---|---|---|
| 🔴 | bs=10 sw=10 sl=64 | 411 | 0.251 | 23,170/34,295/34,295 us | 🔴 +7.5% / 🔴 +120.7% |
| 🟢 | bs=100 sw=10 sl=64 | 955 | 0.583 | 104,997/119,677/119,677 us | 🟢 -21.2% / 🔴 +9.7% |
| ⚪ | bs=1000 sw=10 sl=64 | 1,094 | 0.667 | 901,283/1,043,123/1,043,123 us | ⚪ within ±5% / 🟢 -10.1% |
Baseline details
Latest main cd28761 from same runner
| config | metric | PR | latest main | 7d avg | Δ latest | Δ 7d |
|---|---|---|---|---|---|---|
| bs=10 sw=10 sl=64 | throughput | 411 tuples/sec | 443 tuples/sec | 767.32 tuples/sec | -7.2% | -46.4% |
| bs=10 sw=10 sl=64 | MB/s | 0.251 MB/s | 0.27 MB/s | 0.468 MB/s | -7.0% | -46.4% |
| bs=10 sw=10 sl=64 | p50 | 23,170 us | 21,554 us | 12,772 us | +7.5% | +81.4% |
| bs=10 sw=10 sl=64 | p95 | 34,295 us | 35,689 us | 15,538 us | -3.9% | +120.7% |
| bs=10 sw=10 sl=64 | p99 | 34,295 us | 35,689 us | 18,948 us | -3.9% | +81.0% |
| bs=100 sw=10 sl=64 | throughput | 955 tuples/sec | 928 tuples/sec | 972.51 tuples/sec | +2.9% | -1.8% |
| bs=100 sw=10 sl=64 | MB/s | 0.583 MB/s | 0.566 MB/s | 0.594 MB/s | +3.0% | -1.8% |
| bs=100 sw=10 sl=64 | p50 | 104,997 us | 108,379 us | 103,020 us | -3.1% | +1.9% |
| bs=100 sw=10 sl=64 | p95 | 119,677 us | 151,928 us | 109,070 us | -21.2% | +9.7% |
| bs=100 sw=10 sl=64 | p99 | 119,677 us | 151,928 us | 118,964 us | -21.2% | +0.6% |
| bs=1000 sw=10 sl=64 | throughput | 1,094 tuples/sec | 1,092 tuples/sec | 1,005 tuples/sec | +0.2% | +8.9% |
| bs=1000 sw=10 sl=64 | MB/s | 0.667 MB/s | 0.666 MB/s | 0.613 MB/s | +0.2% | +8.7% |
| bs=1000 sw=10 sl=64 | p50 | 901,283 us | 901,190 us | 1,002,400 us | +0.0% | -10.1% |
| bs=1000 sw=10 sl=64 | p95 | 1,043,123 us | 1,062,439 us | 1,039,228 us | -1.8% | +0.4% |
| bs=1000 sw=10 sl=64 | p99 | 1,043,123 us | 1,062,439 us | 1,069,081 us | -1.8% | -2.4% |
Raw CSV
config_idx,batch_size,schema_width,string_len,num_batches,total_ms,total_tuples,total_bytes,tuples_per_sec,mb_per_sec,lat_p50_us,lat_p95_us,lat_p99_us
0,10,10,64,20,486.67,200,128000,411,0.251,23170.20,34294.69,34294.69
1,100,10,64,20,2094.21,2000,1280000,955,0.583,104997.05,119676.55,119676.55
2,1000,10,64,20,18289.84,20000,12800000,1094,0.667,901283.38,1043122.92,1043122.92|
Pushed 87ca804 to get this green. Three of the grouped bumps are not actually safe patches, and none of the Held back
LicensingEvery remaining bump needed the binary-license bookkeeping that was missing — this is what made
Verified locally (JDK 17)
One follow-up worth considering separately: |
|
👋 Thanks for opening this pull request, @renovate-bot! It looks like the pull request description doesn't quite follow our template yet:
Filling out the template helps reviewers understand and triage your contribution faster. Please edit the description to complete it. This message will disappear automatically once the template is followed. You can find the template prompts by editing the description, or see CONTRIBUTING.md for the full contribution flow. |
87ca804 to
b8353d1
Compare
Edited/Blocked NotificationRenovate will not automatically rebase this PR, because it does not recognize the last commit author and assumes somebody else may have edited the PR. You can manually request rebase by checking the rebase/retry box above. |
This PR contains the following updates:
0.14.6→0.14.71.11.1→1.11.73.14.2→3.14.50.12.0→0.12.22.10.6→2.10.83.9.5→3.9.61.4.6→1.4.94.0.7→4.0.174.0.7→4.0.171.3.23→1.3.291.3.23→1.3.294.0.7→4.0.174.0.7→4.0.171.3.23→1.3.294.0.7→4.0.174.8.184→4.8.1864.8.157→4.8.1864.8.184→4.8.18621.0.0→21.0.2-legacy4.2.15.Final→4.2.17.Final4.2.15.Final→4.2.17.Final4.2.15.Final→4.2.17.Final4.2.15.Final→4.2.17.Final4.2.15.Final→4.2.17.Final4.2.15.Final→4.2.17.Final4.2.15.Final→4.2.17.Final4.2.15.Final→4.2.17.Final4.2.15.Final→4.2.17.Final4.2.15.Final→4.2.17.Final4.2.15.Final→4.2.17.Final4.2.15.Final→4.2.17.Final4.2.15.Final→4.2.17.Final4.2.15.Final→4.2.17.Final3.2→3.2.19.4.20.v20190813→9.4.58.v202508149.4.20.v20190813→9.4.58.v2025081411.0.24→11.0.269.4.20.v20190813→9.4.58.v202508145.13.0.202109080827-r→5.13.5.202508271544-r0.4.3→0.4.43.1.0-M1→3.1.0-M1042.7.10→42.7.133.2.15→3.2.203.2.17→3.2.201.7.26→1.7.361.12.9→1.12.14Warning
Some dependencies could not be looked up. Check the Dependency Dashboard for more information.
Release Notes
scalacenter/sbt-scalafix (ch.epfl.scala:sbt-scalafix)
v0.14.7Compare Source
Pull Requests
sbt/sbt-native-packager (com.github.sbt:sbt-native-packager)
v1.11.7: 1.11.7 SBT Native Packager 📦Compare Source
In This Release
sbt-herokufrom related plugins list (#1731)🐛 Bug Fixes
v1.11.4: 1.11.4Compare Source
sbt-native-packager 1.11.4 is cross published to:
About sbt-native-packager
sbt-native-packager is an sbt plugin to build packages for different operating systems. See https://www.scala-sbt.org/sbt-native-packager/ for the documentation.
Security update
Updates
Behind the scene
Full Changelog: sbt/sbt-native-packager@v1.11.3...v1.11.4
v1.11.3: 1.11.3Compare Source
sbt-native-packager 1.11.3 is cross published to:
About sbt-native-packager
sbt-native-packager is an sbt plugin to build packages for different operating systems. See https://www.scala-sbt.org/sbt-native-packager/ for the documentation.
sbt 2.x migration
Other updates
Behind the scene
New Contributors
Full Changelog: sbt/sbt-native-packager@v1.11.1...v1.11.3
scalapb/scalapb-json4s (com.thesamet.scalapb:scalapb-json4s)
v0.12.2Compare Source
v0.12.1Compare Source
playframework/play-json (com.typesafe.play:play-json)
v2.10.8: Play JSON 2.10.8Compare Source
Noteworthy improvements
This limit can be adjusted using the system property
play.json.parser.maxNestingDepth.We assume a depth of 1000 should be more than sufficient for virtually all real-world use cases.
This change helps prevent both potential
OutOfMemoryErrors andStackOverflowErrors.The latter, however, is not a concern for Play JSON, since it already uses a
@tailrec-optimized parsing method.As a result, Play JSON is not affected by CVE-2025-52999, which specifically addresses
StackOverflowErrorrisks.This improvement is simply an additional safety measure.
Changes
❤️ Thanks to our premium sponsors!
If you find this OSS project useful for work, please consider asking your company to support it by becoming a sponsor.
You can also individually sponsor the project by becoming a backer.
🙇 Thanks to our contributors
Finally, thanks to the community for their help with detailed bug reports, discussions about new features and pull request reviews. This project is only possible due to the help we had from amazing contributors.
Special thanks to all code contributors who helped with this particular release (they are listed below)!
v2.10.7: Play JSON 2.10.7Compare Source
Noteworthy Scala 3 improvements
Changes
Dependency Graphaction (backport #1114) by @ihostage by @mergify[bot]❤️ Thanks to our premium sponsors!
If you find this OSS project useful for work, please consider asking your company to support it by becoming a sponsor.
You can also individually sponsor the project by becoming a backer.
🙇 Thanks to our contributors
Finally, thanks to the community for their help with detailed bug reports, discussions about new features and pull request reviews. This project is only possible due to the help we had from amazing contributors.
Special thanks to all code contributors who helped with this particular release (they are listed below)!
lightbend/scala-logging (com.typesafe.scala-logging:scala-logging)
v3.9.6Compare Source
What's Changed
New Contributors
Full Changelog: scala-garden/scala-logging@v3.9.5...v3.9.6
lightbend/config (com.typesafe:config)
v1.4.9Compare Source
What's Changed
New Contributors
Full Changelog: lightbend/config@v1.4.8...v1.4.9
v1.4.8Compare Source
What's Changed
Full Changelog: lightbend/config@v1.4.7...v1.4.8
v1.4.7Compare Source
What's Changed
New Contributors
Full Changelog: lightbend/config@v1.4.6...v1.4.7
kubernetes-client/java (io.kubernetes:client-java)
v21.0.2-legacyCompare Source
[maven-release-plugin] copy for tag v21.0.2-legacy
v21.0.1Compare Source
v21.0.0-legacyCompare Source
ehcache/sizeof (org.ehcache:sizeof)
v0.4.4Compare Source
pgjdbc/pgjdbc (org.postgresql:postgresql)
v42.7.13Added
search_pathchange via GUC_REPORT (PostgreSQL 18+), so cached plans are no longer used against the wrong schema PR #4259reWriteBatchedInsertsnow merges up to 32768 rows into one multi-valuesINSERT(bounded by the 65535 bind-parameter limit on the extended protocol) instead of capping at 128, which speeds up batches of few-column rows. The newreWriteBatchedInsertsSizeconnection property lowers that cap when set; the default of0uses that maximum. PR #4207autosave=ALWAYS. Controlled by the newflushCacheOnDdlconnection property (defaulttrue); set tofalsefor the prior behaviour. PR #4067connectExecutorconnection property to customize theExecutorused to run the worker task that performs the connection attempt whenloginTimeoutis in effect. The value is the fully qualified name of a class implementingjava.util.concurrent.Executor. With a null value, the default, the driver retains the prior behavior of running the connection attempt on a daemon thread named"PostgreSQL JDBC driver connection thread". The executor must run the task on a thread other than the caller's. Running the attempt on a named thread lets applications that monitor driver-created threads identify it. PR #4165classLoaderStrategyconnection property to control which classloaders the driver searches when loading a class named by a connection property, for examplesocketFactory. The defaultdriver-firstnow falls back to the thread context classloader when the driver's classloader cannot resolve the class, which fixes class loading in non-flat class paths such as Quarkus and OSGi. Setdriverto keep the previous driver-classloader-only behaviour, orcontext-firstto prefer the thread context classloader Issue #2112 PR #4167RECORD, andrefcursorPR #4220LargeObjectBlobInputStreamnow skips by seeking instead of reading, and the driver exposes the server version so it can select the 64-bit large-object API where available PR #4204Changed
loginTimeoutis now aFutureTask(ConnectTask) instead of the hand-rolledConnectThread. When the caller hits the timeout, the task is now cancelled withcancel(true), which interrupts the worker thread rather than letting it run to completion. This makes the connection attempt interruptible, sologinTimeoutcan stop a slow connection attempt instead of leaking a thread. As before, a connection that the worker still manages to establish after the caller gives up is closed by the worker so that it does not leak. There are no public API changes and this should only lead to faster background resource cleanup for connections that time out. PR #4120PGXAConnection.ConnectionHandlernow rejectssetAutoCommit(false)andsetSavepoint(...)during an active XA branch, in addition to the long-rejectedsetAutoCommit(true)/commit()/rollback(). ThesetSavepointrejection was already meant to be in place but the guard misspelled the method name assetSavePoint, so savepoints silently went through. Both changes bring the proxy in line with JTA 1.2 §3.4. PR #4114commitPrepared/rollback-of-prepared now returnXAER_RMFAILinstead ofXAER_RMERRwhen the underlying connection is left in a non-idleTransactionState. Transaction managers (Geronimo, Narayana, Atomikos) treatXAER_RMFAILas retryable on a freshXAResource; the prepared transaction is no longer abandoned. PR #4114getPrimaryKeysfrompg_constraint.conkeyPR #4202Fixed
postgresql-<version>.jarand its detached PGP signature, taken from the same signed build that is uploaded to Maven Central, instead of a leftover SNAPSHOT jar Issue #3812 PR #3814Statement#cancelstate machine by dropping the redundantCANCELLEDstate.killTimerTasknow waits for the state to return toIDLEdirectly, which removes a spin-forever case when more than one thread observes the cancel completing PR #1827.BEGINand the following query to share a network flush Issue #3894 PR #4196reWriteBatchedInsertsno longer throwsIllegalArgumentExceptionwhen batching a parameterlessINSERT(for exampleINSERT INTO t VALUES (1, 2)) of 256 rows or more PR #4207CALLin aCallableStatementno longer hides the native call, so OUT parameter registration works for/* comment */ call proc(?, ?)and similar.Parser.modifyJdbcCallnow skips leading whitespace and SQL comments (both--and/* */) before the call, tolerates a trailing comment after a{ ... }escape, and no longer adds a spurious comma when moving an OUT parameter into a call whose arguments are only a comment Issue #2538 PR #4209PreparedStatement.toString()no longer throws for abyteavalue supplied as text viaPGobject. Hex-format values (\x...) are validated and rendered as abytealiteral, and escape-format values are quoted and cast like any other literal Issue #3757 PR #4201contextClassLoaderof sharedForkJoinPool.commonPool()worker threads, which previously left unrelated tasks on those threads running with anullclassloader Issue #4155 PR #4156PgResultSet#getCharacterStreamwrapsStringin aStringReaderPR #4063PGXAConnectionno longer saves and restores the underlying connection's JDBCautoCommitflag. All XA-protocol SQL (BEGIN,PREPARE TRANSACTION,COMMIT,ROLLBACK,COMMIT PREPARED,ROLLBACK PREPARED, therecover()SELECT) is sent throughQUERY_SUPPRESS_BEGIN, so the caller'sautoCommitvalue is invariant across everyXAResourcecall. Fixes the "2nd phase commit must be issued using an idle connection" failure during recovery on managed datasources that pool connections withautoCommit=false(TomEE, WildFly, WebSphere Liberty) PR #4114PGXAConnection.prepare()now mutates XA state only afterPREPARE TRANSACTIONsucceeds. A failedPREPAREpreviously left the driver thinking the branch was already prepared, so the follow-uprollback(xid)triedROLLBACK PREPAREDagainst a non-existent gid and returnedXAER_RMERR. Transaction managers (Narayana) escalated this toHeuristicMixedException. With the fix,rollback(xid)takes the active-branch path and issues a plainROLLBACK, which the server accepts cleanly. Fixes Issue #3153, Issue #3123. PR #4114search_path. When two schemas held a table with the same name and the same primary or unique index name but a different set of key columns, the driver took the union of both schemas' columns, so the result set could be wrongly rejected as not updatable [PR #4214](https://redirect.github.com/pgjdbc/pgjdbConfiguration
📅 Schedule: (in timezone Etc/UTC)
🚦 Automerge: Disabled by config. Please merge this manually once you are satisfied.
♻ Rebasing: Whenever PR becomes conflicted, or you tick the rebase/retry checkbox.
👻 Immortal: This PR will be recreated if closed unmerged. Get config help if that's undesired.
This PR was generated by Mend Renovate. View the repository job log.