Skip to content

Bump quarkus.platform.version from 3.39.0 to 3.39.1 - #367

Merged
thescouser89 merged 1 commit into
mainfrom
dependabot/maven/quarkus.platform.version-3.39.1
Sep 9, 2026
Merged

Bump quarkus.platform.version from 3.39.0 to 3.39.1#367
thescouser89 merged 1 commit into
mainfrom
dependabot/maven/quarkus.platform.version-3.39.1

Conversation

@dependabot

@dependabot dependabot Bot commented on behalf of github Sep 8, 2026

Copy link
Copy Markdown
Contributor

Bumps quarkus.platform.version from 3.39.0 to 3.39.1.
Updates io.quarkus:quarkus-bom from 3.39.0 to 3.39.1

Release notes

Sourced from io.quarkus:quarkus-bom's releases.

3.39.1

Complete changelog

  • #48943 - From Quarkus 3.22, Database dev services not reused if the unit test is using a @QuarkusTestResource
  • #51130 - Remote Dev fails when using hibernate-reactive extension
  • #55389 - Fix @RunOnVirtualThread annotation in combination with blocking endpoints
  • #55907 - Quarkus 3.38 Date serialization issue
  • #55958 - container-image-jib: no progress output while the image is pushed, because ProgressEvent is never subscribed to
  • #55959 - Jib container push progress log
  • #56009 - Dev UI Dev MCP endpoint hangs indefinitely (no response, no error) when a JSON-RPC request's id is a string
  • #56064 - quarkus-rest-jackson: reflection-free (de)serializers treat a Map subclass as a bean and drop every map entry
  • #56070 - quarkus-spring-security may not fail the build when @PostAuthorize, @PreFilter or @PostFilter are used
  • #56079 - Skip Hibernate dev integrator in remote server-side dev mode
  • #56080 - MongoDB Panache: Session-commit on transaction rollback
  • #56086 - [3.39] Do not set an invalid country code when generating the Quarkus Dev CA
  • #56087 - [3.39] Handle string JSON-RPC ids and always respond on the Dev MCP endpoint (3.39 backport)
  • #56088 - Fail the build when unsupported Spring Security annotations are used
  • #56092 - [3.39] Revert "Disable the Quarkus Dev CA generation test on Windows"
  • #56101 - Document that CORS cannot be configured both programmatically and with properties
  • #56104 - quarkus-config-doc-maven-plugin picks up things from git worktrees that it should ignore
  • #56105 - Don't descend into nested git checkouts when scanning for config-doc target directories
  • #56130 - Register terminal provider SPI and defer FFM init for native images
  • #56131 - docs: clean up independently maintained CORS guide
  • #56132 - Redis replication with topology=static does not respect host ordering - Set loses master/replica order
  • #56158 - REST Client: @RestClient on the interface fails the build with a duplicate annotation since 3.32
  • #56159 - Ignore a @RestClient qualifier placed on the REST Client interface
  • #56166 - Fix MongoDB Panache committing sessions after a JTA transaction timeout
  • #56177 - Bump io.micrometer:micrometer-bom from 1.17.0 to 1.17.1
  • #56183 - Redis: make sure the configured hosts are ordered
  • #56192 - Do not rebuild the application for every launch of a QuarkusMainTest
  • #56197 - Upgrade aesh, aesh-readline, fix ffm downcall and customizers
  • #56204 - Switch to JavaParser for generating build items doc
Commits
  • b55a476 [RELEASE] - Bump version to 3.39.1
  • cc611c6 Merge pull request #56211 from gsmet/3.39.1-backports-1
  • b7bb3c6 Upgrade aesh to 3.17.2 and aesh-readline to 3.17.1
  • 3f6dd21 Redis: make sure the configured hosts are ordered
  • 6bc6c8c Switch to JavaParser for generating build items doc
  • b065964 Add non-regression test for mutable jar + Hibernate ORM in remote dev mode
  • 232a3cf Hibernate ORM - Skip dev integrator in remote server-side dev mode
  • 118a1e8 Do not rebuild the application for every launch of a QuarkusMainTest
  • e606737 Bump io.micrometer:micrometer-bom from 1.17.0 to 1.17.1
  • 9125aec Confine Dev UI workspace JSON-RPC operations to the project root
  • Additional commits viewable in compare view

Updates io.quarkus:quarkus-maven-plugin from 3.39.0 to 3.39.1

Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting @dependabot rebase.


Dependabot commands and options

You can trigger Dependabot actions by commenting on this PR:

  • @dependabot rebase will rebase this PR
  • @dependabot recreate will recreate this PR, overwriting any edits that have been made to it
  • @dependabot show <dependency name> ignore conditions will show all of the ignore conditions of the specified dependency
  • @dependabot ignore this major version will close this PR and stop Dependabot creating any more for this major version (unless you reopen the PR or upgrade to it yourself)
  • @dependabot ignore this minor version will close this PR and stop Dependabot creating any more for this minor version (unless you reopen the PR or upgrade to it yourself)
  • @dependabot ignore this dependency will close this PR and stop Dependabot creating any more for this dependency (unless you reopen the PR or upgrade to it yourself)

Bumps `quarkus.platform.version` from 3.39.0 to 3.39.1.

Updates `io.quarkus:quarkus-bom` from 3.39.0 to 3.39.1
- [Release notes](https://github.com/quarkusio/quarkus/releases)
- [Commits](quarkusio/quarkus@3.39.0...3.39.1)

Updates `io.quarkus:quarkus-maven-plugin` from 3.39.0 to 3.39.1

---
updated-dependencies:
- dependency-name: io.quarkus:quarkus-bom
  dependency-version: 3.39.1
  dependency-type: direct:production
  update-type: version-update:semver-patch
- dependency-name: io.quarkus:quarkus-maven-plugin
  dependency-version: 3.39.1
  dependency-type: direct:development
  update-type: version-update:semver-patch
...

Signed-off-by: dependabot[bot] <support@github.com>
@dependabot dependabot Bot added dependencies Pull requests that update a dependency file java Pull requests that update java code labels Sep 8, 2026
@github-actions

github-actions Bot commented Sep 8, 2026

Copy link
Copy Markdown
Contributor

Mend Scan Results

Status: ⚠️ Findings detected

⚠️ SCA findings detected

SCA scan output



Identified 342 dependencies

Detected 21 vulnerabilities (1 Critical, 12 High, 7 Medium, 1 Low)

+----------+-----------------------------------------------+----------------+--------------------------------------------------------------------------------------------------+
| SEVERITY |                    LIBRARY                    |       ID       |                                             TOP FIX                                              |
+----------+-----------------------------------------------+----------------+--------------------------------------------------------------------------------------------------+
| CRITICAL | httpclient5-5.6.1.jar                         | CVE-2026-71290 | Upgrade to version  https://github.com/apache/httpcomponents-client.git - rel/v5.6.4,            |
|          |                                               |                | org.apache.httpcomponents.client5:httpclient5:5.6.4                                              |
+----------+-----------------------------------------------+----------------+--------------------------------------------------------------------------------------------------+
| HIGH     | jsoup-1.23.1.jar                              | CVE-2026-75140 | N/A                                                                                              |
+----------+-----------------------------------------------+----------------+--------------------------------------------------------------------------------------------------+
| HIGH     | resteasy-core-6.2.16.Final.jar                | CVE-2026-17615 | N/A                                                                                              |
+----------+-----------------------------------------------+----------------+--------------------------------------------------------------------------------------------------+
| HIGH     | undertow-core-2.2.39.Final.jar                | CVE-2024-3884  | Upgrade to version io.undertow:undertow-core:2.4.0.Beta1,io.undertow:undertow-core:2.2.39.Final, |
|          |                                               |                | io.undertow:undertow-core:2.3.21.Final                                                           |
+----------+-----------------------------------------------+----------------+--------------------------------------------------------------------------------------------------+
| HIGH     | undertow-core-2.2.39.Final.jar                | CVE-2024-4027  | Upgrade to version  https://github.com/undertow-io/undertow.git - 2.3.21.Final,                  |
|          |                                               |                | io.undertow:undertow-core:2.3.21.Final,io.undertow:undertow-core:2.2.39.Final,                   |
|          |                                               |                | https://github.com/undertow-io/undertow.git - 2.4.0.Beta1,io.undertow:undertow-core:2.4.0.Beta1  |
+----------+-----------------------------------------------+----------------+--------------------------------------------------------------------------------------------------+
| HIGH     | undertow-core-2.2.39.Final.jar                | CVE-2026-15554 | N/A                                                                                              |
+----------+-----------------------------------------------+----------------+--------------------------------------------------------------------------------------------------+
| HIGH     | undertow-core-2.2.39.Final.jar                | CVE-2026-15561 | N/A                                                                                              |
+----------+-----------------------------------------------+----------------+--------------------------------------------------------------------------------------------------+
| HIGH     | undertow-core-2.2.39.Final.jar                | CVE-2026-5680  | Upgrade to version  https://github.com/undertow-io/undertow.git - 2.4.3.Final,                   |
|          |                                               |                | io.undertow:undertow-core:2.4.3.Final                                                            |
+----------+-----------------------------------------------+----------------+--------------------------------------------------------------------------------------------------+
| HIGH     | undertow-core-2.2.39.Final.jar                | CVE-2026-81624 | N/A                                                                                              |
+----------+-----------------------------------------------+----------------+--------------------------------------------------------------------------------------------------+
| HIGH     | undertow-servlet-2.2.39.Final.jar             | CVE-2026-81624 | N/A                                                                                              |
+----------+-----------------------------------------------+----------------+--------------------------------------------------------------------------------------------------+
| HIGH     | undertow-websockets-jsr-2.2.39.Final.jar      | CVE-2026-15565 | N/A                                                                                              |
+----------+-----------------------------------------------+----------------+--------------------------------------------------------------------------------------------------+
| HIGH     | undertow-websockets-jsr-2.2.39.Final.jar      | CVE-2026-81624 | N/A                                                                                              |
+----------+-----------------------------------------------+----------------+--------------------------------------------------------------------------------------------------+
| HIGH     | wildfly-elytron-password-impl-2.9.2.Final.jar | CVE-2026-19611 | N/A                                                                                              |
+----------+-----------------------------------------------+----------------+--------------------------------------------------------------------------------------------------+
| MEDIUM   | httpclient5-5.6.1.jar                         | CVE-2026-64607 | Upgrade to version org.apache.httpcomponents.client5:httpclient5:5.6.3                           |
+----------+-----------------------------------------------+----------------+--------------------------------------------------------------------------------------------------+
| MEDIUM   | jackson-databind-2.22.0.jar                   | CVE-2026-19032 | Upgrade to version tools.jackson.core:jackson-databind:3.2.2,                                    |
|          |                                               |                | com.fasterxml.jackson.core:jackson-databind:2.22.2,                                              |
|          |                                               |                | com.fasterxml.jackson.core:jackson-databind:2.21.6,tools.jackson.core:jackson-databind:3.1.6,    |
|          |                                               |                | com.fasterxml.jackson.core:jackson-databind:2.18.10                                              |
+----------+-----------------------------------------------+----------------+--------------------------------------------------------------------------------------------------+
| MEDIUM   | jackson-databind-2.22.0.jar                   | CVE-2026-54515 | Upgrade to version com.fasterxml.jackson.core:jackson-databind:2.22.1,                           |
|          |                                               |                | https://github.com/FasterXML/jackson-databind.git - jackson-databind-2.18.9,                     |
|          |                                               |                | https://github.com/FasterXML/jackson-databind.git - jackson-databind-2.21.5,                     |
|          |                                               |                | https://github.com/FasterXML/jackson-databind.git - jackson-databind-2.22.1,                     |
|          |                                               |                | https://github.com/FasterXML/jackson-databind.git - jackson-databind-3.1.4,                      |
|          |                                               |                | com.fasterxml.jackson.core:jackson-databind:2.21.5                                               |
+----------+-----------------------------------------------+----------------+--------------------------------------------------------------------------------------------------+
| MEDIUM   | jackson-databind-2.22.0.jar                   | CVE-2026-59889 | Upgrade to version com.fasterxml.jackson.core:jackson-databind:2.22.1,                           |
|          |                                               |                | tools.jackson.core:jackson-databind:3.1.5,com.fasterxml.jackson.core:jackson-databind:2.21.5,    |
|          |                                               |                | tools.jackson.core:jackson-databind:3.2.1                                                        |
+----------+-----------------------------------------------+----------------+--------------------------------------------------------------------------------------------------+
| MEDIUM   | jackson-databind-2.22.0.jar                   | CVE-2026-77310 | Upgrade to version com.fasterxml.jackson.core:jackson-databind:2.18.9,                           |
|          |                                               |                | tools.jackson.core:jackson-databind:3.1.5,com.fasterxml.jackson.core:jackson-databind:2.22.1,    |
|          |                                               |                | com.fasterxml.jackson.core:jackson-databind:2.21.5,tools.jackson.core:jackson-databind:3.2.1     |
+----------+-----------------------------------------------+----------------+--------------------------------------------------------------------------------------------------+
| MEDIUM   | jackson-databind-2.22.0.jar                   | CVE-2026-83557 | Upgrade to version tools.jackson.core:jackson-databind:3.1.6,                                    |
|          |                                               |                | com.fasterxml.jackson.core:jackson-databind:2.22.2,                                              |
|          |                                               |                | com.fasterxml.jackson.core:jackson-databind:2.18.10,                                             |
|          |                                               |                | com.fasterxml.jackson.core:jackson-databind:2.21.6,tools.jackson.core:jackson-databind:3.2.2     |
+----------+-----------------------------------------------+----------------+--------------------------------------------------------------------------------------------------+
| MEDIUM   | undertow-core-2.2.39.Final.jar                | CVE-2026-19879 | N/A                                                                                              |
+----------+-----------------------------------------------+----------------+--------------------------------------------------------------------------------------------------+
| LOW      | LatencyUtils-2.0.3.jar                        | CVE-2026-82596 | N/A                                                                                              |
+----------+-----------------------------------------------+----------------+--------------------------------------------------------------------------------------------------+


Paths at risk

P = policy violation
MSC = malicious vulnerability
CRITICAL/HIGH/MEDIUM/LOW = vulnerability severity

quarkus-elytron-security-ldap-3.39.1.jar
|-- quarkus-elytron-security-3.39.1.jar
	|-- quarkus-elytron-security-common-3.39.1.jar
		|-- wildfly-elytron-password-impl-2.9.2.Final.jar [1 HIGH]
	|-- wildfly-elytron-password-impl-2.9.2.Final.jar [1 HIGH]
	|-- wildfly-elytron-realm-2.9.2.Final.jar
		|-- wildfly-elytron-password-impl-2.9.2.Final.jar [1 HIGH]
|-- wildfly-elytron-realm-ldap-2.9.2.Final.jar
	|-- wildfly-elytron-client-2.9.2.Final.jar
		|-- wildfly-elytron-credential-source-impl-2.9.2.Final.jar
			|-- wildfly-elytron-password-impl-2.9.2.Final.jar [1 HIGH]
		|-- wildfly-elytron-credential-store-2.9.2.Final.jar
			|-- wildfly-elytron-password-impl-2.9.2.Final.jar [1 HIGH]
		|-- wildfly-elytron-password-impl-2.9.2.Final.jar [1 HIGH]
quarkus-micrometer-opentelemetry-3.39.1.jar
|-- quarkus-micrometer-3.39.1.jar
	|-- micrometer-core-1.17.1.jar
		|-- httpclient5-5.6.1.jar [1 CRITICAL, 1 MEDIUM]
	|-- LatencyUtils-2.0.3.jar [1 LOW]
quarkus-oidc-3.39.1.jar
|-- quarkus-oidc-common-3.39.1.jar
	|-- smallrye-mutiny-vertx-web-client-3.23.0.jar
		|-- jackson-databind-2.22.0.jar [5 MEDIUM]
		|-- vertx-web-client-4.5.32.jar
			|-- jackson-databind-2.22.0.jar [5 MEDIUM]
|-- quarkus-vertx-3.39.1.jar
	|-- jackson-databind-2.22.0.jar [5 MEDIUM]
	|-- smallrye-mutiny-vertx-core-3.23.0.jar
		|-- jackson-databind-2.22.0.jar [5 MEDIUM]
quarkus-resteasy-jackson-3.39.1.jar
|-- quarkus-jackson-3.39.1.jar
	|-- jackson-databind-2.22.0.jar [5 MEDIUM]
	|-- vertx-core-4.5.32.jar
		|-- jackson-databind-2.22.0.jar [5 MEDIUM]
|-- resteasy-jackson2-provider-6.2.16.Final.jar
	|-- jackson-databind-2.22.0.jar [5 MEDIUM]
	|-- jackson-jakarta-rs-base-2.22.0.jar
		|-- jackson-databind-2.22.0.jar [5 MEDIUM]
	|-- jackson-module-jakarta-xmlbind-annotations-2.22.0.jar
		|-- jackson-databind-2.22.0.jar [5 MEDIUM]
	|-- json-patch-1.13.jar
		|-- jackson-databind-2.22.0.jar [5 MEDIUM]
		|-- jackson-coreutils-2.0.jar
			|-- jackson-databind-2.22.0.jar [5 MEDIUM]
	|-- resteasy-core-6.2.16.Final.jar [1 HIGH]
quarkus-resteasy-mutiny-3.39.1.jar
|-- quarkus-resteasy-mutiny-common-3.39.1.jar
	|-- quarkus-resteasy-common-3.39.1.jar
		|-- jackson-databind-2.22.0.jar [5 MEDIUM]
		|-- microprofile-config-3.0.1.Final.jar
			|-- resteasy-core-6.2.16.Final.jar [1 HIGH]
		|-- resteasy-core-6.2.16.Final.jar [1 HIGH]
	|-- resteasy-client-6.2.16.Final.jar
		|-- resteasy-core-6.2.16.Final.jar [1 HIGH]
|-- quarkus-resteasy-3.39.1.jar
	|-- quarkus-resteasy-server-common-3.39.1.jar
		|-- resteasy-cdi-6.2.16.Final.jar
			|-- resteasy-core-6.2.16.Final.jar [1 HIGH]
quarkus-smallrye-health-3.39.1.jar
|-- quarkus-vertx-http-3.39.1.jar
	|-- jackson-databind-2.22.0.jar [5 MEDIUM]
	|-- vertx-web-4.5.32.jar
		|-- jackson-databind-2.22.0.jar [5 MEDIUM]
client-1.2.4-SNAPSHOT.jar
|-- jackson-databind-2.22.0.jar [5 MEDIUM]
|-- undertow-websockets-jsr-2.2.39.Final.jar [2 HIGH]
	|-- undertow-core-2.2.39.Final.jar [6 HIGH, 1 MEDIUM]
	|-- undertow-servlet-2.2.39.Final.jar [1 HIGH]
		|-- undertow-core-2.2.39.Final.jar [6 HIGH, 1 MEDIUM]
|-- api-1.2.4-SNAPSHOT.jar
	|-- jackson-databind-2.22.0.jar [5 MEDIUM]
|-- common-1.2.4-SNAPSHOT.jar
	|-- undertow-core-2.2.39.Final.jar [6 HIGH, 1 MEDIUM]
	|-- httpclient5-5.6.1.jar [1 CRITICAL, 1 MEDIUM]
	|-- keycloak-authz-client-26.0.12.jar
		|-- jackson-databind-2.22.0.jar [5 MEDIUM]
		|-- keycloak-client-common-synced-26.0.12.jar
			|-- jackson-databind-2.22.0.jar [5 MEDIUM]
pnc-api-3.5.2-jakarta.jar
|-- jackson-databind-2.22.0.jar [5 MEDIUM]
pnc-common-3.5.4-jakarta.jar
|-- jackson-databind-2.22.0.jar [5 MEDIUM]
|-- jackson-datatype-jdk8-2.22.0.jar
	|-- jackson-databind-2.22.0.jar [5 MEDIUM]
|-- jackson-datatype-jsr310-2.22.0.jar
	|-- jackson-databind-2.22.0.jar [5 MEDIUM]
|-- jackson-module-parameter-names-2.22.0.jar
	|-- jackson-databind-2.22.0.jar [5 MEDIUM]
|-- pom-manipulation-common-lite-5.5.jar
	|-- jackson-databind-2.22.0.jar [5 MEDIUM]
	|-- reports-model-2.6.9.jar
		|-- jackson-databind-2.22.0.jar [5 MEDIUM]
|-- pnc-api-3.6.0-SNAPSHOT.jar
	|-- jackson-databind-2.22.0.jar [5 MEDIUM]
|-- jsoup-1.23.1.jar [1 HIGH]


No Policy violations were detected

Project 'build-driver' was updated, for more information, visit the Mend platform: https://ibmets.whitesourcesoftware.com/app/orgs/Enterprise%20Applications/applications/summary?project=f5dd621d-c704-4397-a82f-8fe49c792cce
Or the Core UI: https://ibmets.whitesourcesoftware.com/Wss/WSS.html#!project;token=9fa8cea870c44776a509af8062b49dac09e847430c4a45319a264ecbdf350f69

Mend AI scan succeeded.

Support Token: 0f43added8c314a218d435ee9cb197d3d1788835831383
SAST scan output
*no findings*

Full logs and artifacts

@thescouser89
thescouser89 merged commit e39f044 into main Sep 9, 2026
3 checks passed
@dependabot
dependabot Bot deleted the dependabot/maven/quarkus.platform.version-3.39.1 branch September 9, 2026 18:12
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

dependencies Pull requests that update a dependency file java Pull requests that update java code

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant