Skip to content

Bump the java-patch-and-minor group across 1 directory with 2 updates - #191

Open
dependabot[bot] wants to merge 1 commit into
mainfrom
dependabot/maven/java-patch-and-minor-a908578cb4
Open

Bump the java-patch-and-minor group across 1 directory with 2 updates#191
dependabot[bot] wants to merge 1 commit into
mainfrom
dependabot/maven/java-patch-and-minor-a908578cb4

Conversation

@dependabot

@dependabot dependabot Bot commented on behalf of github Aug 15, 2026

Copy link
Copy Markdown
Contributor

Bumps the java-patch-and-minor group with 2 updates in the / directory: com.microsoft.signalr:signalr and org.apache.httpcomponents.client5:httpclient5.

Updates com.microsoft.signalr:signalr from 8.0.29 to 8.0.30

Release notes

Sourced from com.microsoft.signalr:signalr's releases.

.NET 8.0.30

Release

What's Changed

New Contributors

Full Changelog: dotnet/aspnetcore@v8.0.29...v8.0.30

Commits
  • f336360 Merged PR 63140: Revert System.Security.Cryptography.Xml to the released version
  • 8577938 Merged PR 63133: [internal/release/8.0] Add .npmrc files next to yarn.lock files
  • b4e3030 Revert "TEMP: Add verbose yarn/npm restore diagnostics for ws@7.5.11 investig...
  • c73d33d Suppress NU1902 AngleSharp audit warning per-project instead of globally
  • 21c07ef Update stale yarn.lock files to resolve ws@^7.5.11
  • bd988fa TEMP: Add verbose yarn/npm restore diagnostics for ws@7.5.11 investigation
  • a64050d TEMP: Suppress NU1902 AngleSharp audit warning for CI diagnosis
  • aafcb55 Add .npmrc files next to yarn.lock files
  • f936636 Merged PR 63080: merge from public
  • 948ce52 Update dependencies from https://github.com/dotnet/arcade build 20260721.5 (#...
  • Additional commits viewable in compare view

Updates org.apache.httpcomponents.client5:httpclient5 from 5.6.3 to 5.6.4

Changelog

Sourced from org.apache.httpcomponents.client5:httpclient5's changelog.

Release 5.6.4

This maintenance release fixes SSL parameter application in the async TLS upgrade strategy.

Change Log

  • BearerScheme to reject control characters in bearer token. Contributed by Javid Khan

  • Corrects application of SSL parameters in the async TLS upgrade method. Contributed by Oleg Kalnichevski

Commits
  • 36508ce HttpClient 5.6.4 release
  • 59b3d2e Updated release notes for HttpClient 5.6.4 release
  • c0af759 reject control characters in bearer token in BearerScheme
  • 2422b6c Corrects application of SSL parameters in the async TLS upgrade method
  • 66452ea Upgraded HttpClient version to 5.6.4-SNAPSHOT
  • See full diff in compare view

Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting @dependabot rebase.


Dependabot commands and options

You can trigger Dependabot actions by commenting on this PR:

  • @dependabot rebase will rebase this PR
  • @dependabot recreate will recreate this PR, overwriting any edits that have been made to it
  • @dependabot show <dependency name> ignore conditions will show all of the ignore conditions of the specified dependency
  • @dependabot ignore <dependency name> major version will close this group update PR and stop Dependabot creating any more for the specific dependency's major version (unless you unignore this specific dependency's major version or upgrade to it yourself)
  • @dependabot ignore <dependency name> minor version will close this group update PR and stop Dependabot creating any more for the specific dependency's minor version (unless you unignore this specific dependency's minor version or upgrade to it yourself)
  • @dependabot ignore <dependency name> will close this group update PR and stop Dependabot creating any more for the specific dependency (unless you unignore this specific dependency or upgrade to it yourself)
  • @dependabot unignore <dependency name> will remove all of the ignore conditions of the specified dependency
  • @dependabot unignore <dependency name> <ignore condition> will remove the ignore condition of the specified dependency and ignore conditions

Bumps the java-patch-and-minor group with 2 updates in the / directory: [com.microsoft.signalr:signalr](https://github.com/dotnet/aspnetcore) and [org.apache.httpcomponents.client5:httpclient5](https://github.com/apache/httpcomponents-client).


Updates `com.microsoft.signalr:signalr` from 8.0.29 to 8.0.30
- [Release notes](https://github.com/dotnet/aspnetcore/releases)
- [Changelog](https://github.com/dotnet/aspnetcore/blob/main/docs/ReleasePlanning.md)
- [Commits](dotnet/aspnetcore@v8.0.29...v8.0.30)

Updates `org.apache.httpcomponents.client5:httpclient5` from 5.6.3 to 5.6.4
- [Changelog](https://github.com/apache/httpcomponents-client/blob/rel/v5.6.4/RELEASE_NOTES.txt)
- [Commits](apache/httpcomponents-client@rel/v5.6.3...rel/v5.6.4)

---
updated-dependencies:
- dependency-name: com.microsoft.signalr:signalr
  dependency-version: 8.0.30
  dependency-type: direct:production
  update-type: version-update:semver-patch
  dependency-group: java-patch-and-minor
- dependency-name: org.apache.httpcomponents.client5:httpclient5
  dependency-version: 5.6.4
  dependency-type: direct:production
  update-type: version-update:semver-patch
  dependency-group: java-patch-and-minor
...

Signed-off-by: dependabot[bot] <support@github.com>
@dependabot dependabot Bot added dependencies Pull requests that update a dependency file security Security-related changes, fixes, or advisories labels Aug 15, 2026
@dependabot
dependabot Bot requested a review from a team as a code owner August 15, 2026 22:53
@dependabot dependabot Bot added dependencies Pull requests that update a dependency file security Security-related changes, fixes, or advisories labels Aug 15, 2026
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

dependencies Pull requests that update a dependency file security Security-related changes, fixes, or advisories

Projects

None yet

Development

Successfully merging this pull request may close these issues.

0 participants