Skip to content

chore(deps): Bump version.quarkus from 3.35.3 to 3.35.4#33

Merged
github-actions[bot] merged 1 commit into
mainfrom
dependabot/maven/version.quarkus-3.35.4
May 22, 2026
Merged

chore(deps): Bump version.quarkus from 3.35.3 to 3.35.4#33
github-actions[bot] merged 1 commit into
mainfrom
dependabot/maven/version.quarkus-3.35.4

Conversation

@dependabot

@dependabot dependabot Bot commented on behalf of github May 22, 2026

Copy link
Copy Markdown
Contributor

Bumps version.quarkus from 3.35.3 to 3.35.4.
Updates io.quarkus:quarkus-bom from 3.35.3 to 3.35.4

Release notes

Sourced from io.quarkus:quarkus-bom's releases.

3.35.4

Complete changelog

  • #51109 - Smallrye OpenAPI generation for SSE with Multi return type generates array type
  • #53479 - x-smallrye-profile Profile filtering not working properly
  • #53798 - Update remaining actions to pinned shas
  • #53844 - Bump smallrye-open-api.version from 4.3.0 to 4.3.1
  • #53916 - Add support for more Jackson annotations in generated reflection-free serializers
  • #53944 - Bump the hibernate group with 9 updates
  • #53946 - [3.35.1] Hibernate IllegalArgumentException is not a subtype
  • #53964 - StackOverflowError in Hibernate metadata processing since 3.35 for generic AttributeConverter
  • #54060 - Allow WebDependencyJarBuildItem to carry import mappings directly
  • #54085 - Improve Micrometer test resilience
  • #54091 - mTLS auth mechanism throws NPE when proxy "forwarded" header indicate HTTPS in the HTTP request
  • #54093 - Using reflection-free serializers breaks in 3.35
  • #54127 - quarkus-opentelemetry native image on JDK 25: IllegalArgumentException: Receiver type ManagementSupport$$Lambda is not an instance of com.sun.management.OperatingSystemMXBean at runtime
  • #54140 - Fix CNFE for CpuMethods otel class
  • #54146 - SunPKCS provider is not available at runtime
  • #54147 - Apply security provider specific configuration at runtime
  • #54148 - Bump Narayana from 7.3.3.Final to 7.3.4.Final
  • #54150 - Bump the hibernate group across 1 directory with 14 updates
  • #54188 - Update JAXB to 4.0.8
  • #54189 - Generate reflection-free Jackson serializers only for public classes
  • #54199 - docs: replace Markdown xml fence with AsciiDoc source block
  • #54208 - Bump smallrye-open-api from 4.3.1 to 4.3.3
  • #54242 - Prevent NPE in mTLS auth mech when communication with a trusted proxy happens over HTTP protocol but headers indicate HTTPS
  • #54264 - Fix NPE in RemoteUserAttribute with anonymous identity
  • #54310 - Prometheus compression header fix
Commits
  • 1c1e9c6 [RELEASE] - Bump version to 3.35.4
  • 6167502 Merge pull request #54328 from gsmet/3.35.4-backports-1
  • 337bfcf fix(security): prevent NPE in mTLS auth mech & trusted proxy
  • 86fa317 Fix NPE in RemoteUserAttribute with anonymous identity
  • e111dc1 Prometheus compression header fix
  • 0b22ecd improve Micrometer test resilience
  • 353fb87 Bump smallrye-open-api from 4.3.1 to 4.3.3
  • 58c97a9 Bump the hibernate group across 1 directory with 14 updates
  • ca4182f Bump the hibernate group with 9 updates
  • 129eb84 Update JAXB to 4.0.8
  • Additional commits viewable in compare view

Updates io.quarkus:quarkus-maven-plugin from 3.35.3 to 3.35.4

Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting @dependabot rebase.


Dependabot commands and options

You can trigger Dependabot actions by commenting on this PR:

  • @dependabot rebase will rebase this PR
  • @dependabot recreate will recreate this PR, overwriting any edits that have been made to it
  • @dependabot show <dependency name> ignore conditions will show all of the ignore conditions of the specified dependency
  • @dependabot ignore this major version will close this PR and stop Dependabot creating any more for this major version (unless you reopen the PR or upgrade to it yourself)
  • @dependabot ignore this minor version will close this PR and stop Dependabot creating any more for this minor version (unless you reopen the PR or upgrade to it yourself)
  • @dependabot ignore this dependency will close this PR and stop Dependabot creating any more for this dependency (unless you reopen the PR or upgrade to it yourself)

Bumps `version.quarkus` from 3.35.3 to 3.35.4.

Updates `io.quarkus:quarkus-bom` from 3.35.3 to 3.35.4
- [Release notes](https://github.com/quarkusio/quarkus/releases)
- [Commits](quarkusio/quarkus@3.35.3...3.35.4)

Updates `io.quarkus:quarkus-maven-plugin` from 3.35.3 to 3.35.4

---
updated-dependencies:
- dependency-name: io.quarkus:quarkus-bom
  dependency-version: 3.35.4
  dependency-type: direct:production
  update-type: version-update:semver-patch
- dependency-name: io.quarkus:quarkus-maven-plugin
  dependency-version: 3.35.4
  dependency-type: direct:production
  update-type: version-update:semver-patch
...

Signed-off-by: dependabot[bot] <support@github.com>
@dependabot dependabot Bot added dependencies Pull requests that update a dependency file java Pull requests that update java code labels May 22, 2026
@github-actions github-actions Bot enabled auto-merge (squash) May 22, 2026 11:38
@github-actions github-actions Bot merged commit b6d2d38 into main May 22, 2026
16 checks passed
@dependabot dependabot Bot deleted the dependabot/maven/version.quarkus-3.35.4 branch May 22, 2026 11:44
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

dependencies Pull requests that update a dependency file java Pull requests that update java code

Projects

None yet

Development

Successfully merging this pull request may close these issues.

0 participants