Skip to content

Bump org.hibernate:hibernate-core from 6.6.13.Final to 7.2.2.Final in /java/hibernate/examples/pet-clinic-app#32

Closed
dependabot[bot] wants to merge 1 commit into
mainfrom
dependabot/gradle/java/hibernate/examples/pet-clinic-app/org.hibernate-hibernate-core-7.2.2.Final
Closed

Bump org.hibernate:hibernate-core from 6.6.13.Final to 7.2.2.Final in /java/hibernate/examples/pet-clinic-app#32
dependabot[bot] wants to merge 1 commit into
mainfrom
dependabot/gradle/java/hibernate/examples/pet-clinic-app/org.hibernate-hibernate-core-7.2.2.Final

Conversation

@dependabot

@dependabot dependabot Bot commented on behalf of github Jan 29, 2026

Copy link
Copy Markdown
Contributor

Bumps org.hibernate:hibernate-core from 6.6.13.Final to 7.2.2.Final.

Release notes

Sourced from org.hibernate:hibernate-core's releases.

Release 7.2.2

Hibernate ORM 7.2.2.Final released

Today, we published a new release of Hibernate ORM 7.2: 7.2.2.Final.

You can find the full list of 7.2.2.Final changes here.

What's new

  • See the website for requirements and compatibilities.
  • See the What's New guide for details about new features and capabilities.
  • See the Migration Guide for details about migration.

Conclusion

For additional details, see:

See also the following resources related to supported APIs:

Visit the website for details on getting in touch with us.

Release 7.2.1

Hibernate ORM 7.2.1.Final released

Today, we published a new release of Hibernate ORM 7.2: 7.2.1.Final.

You can find the full list of 7.2.1.Final changes here.

What's new

  • See the website for requirements and compatibilities.
  • See the What's New guide for details about new features and capabilities.
  • See the Migration Guide for details about migration.

Conclusion

... (truncated)

Changelog

Sourced from org.hibernate:hibernate-core's changelog.

Changes in 7.2.2.Final (January 27, 2026)

https://hibernate.atlassian.net/projects/HHH/versions/37206

** Bug * HHH-20095 New SchemaValidator nullability check should only consider explicitly declared nullability * HHH-20094 New SchemaValidator nullability check rejects Envers revtype column * HHH-20087 NPE with StatelessSession + Bean Validation * HHH-20069 DB2iDialect.rowId causes an error in merge queries * HHH-19999 Caching APIs use Comparator<?> for version comparison in Hibernate ORM 7.2.0.Final * HHH-19192 Bulk delete of owner with soft-delete element-collection physically deletes the collection rows * HHH-18835 AssertionError when executing insert-select

Changes in 7.2.1.Final (January 15, 2026)

https://hibernate.atlassian.net/projects/HHH/versions/36872

** Bug * HHH-20048 ByteArrayJavaType#isInstance wrongly considers byte[] instead of Byte[] to be an instance * HHH-20041 DB2 for z IN tuple list predicate performs badly * HHH-20037 MappedSuperClasses can be enhanced more than once resulting in Duplicate annotation interface org...EnhancementInfo Exception * HHH-20032 SubSequence.subSequence violates CharSequence contract for start == end == length() * HHH-20027 Fix failing parsing of PostgreSQL canonical lock_timeout formats (0, ms, s, min, h) * HHH-20015 Hibernate Maven Plugin 7.x does not include maven project dependencies in the enhancement classpath * HHH-20008 Bad performance of MEMBER OF translation * HHH-20005 SchemaUpdateGeneratingOnlyScriptFileTest fails if executed after PrimaryKeyColumnOrderTest * HHH-19985 Subquery embedded value selection uses wrong nested attribute type for extraction * HHH-19976 AdjustableBasicType wrongly creates derived type with existing name causing trouble for Envers * HHH-19964 ClassCastException in AbstractJsonFormatMapper * HHH-19962 Wrong Values used with Subquery and same name Attributes * HHH-19935 UuidVersion7Strategy can generate cosecutive UUIDs that are equal * HHH-19929 DB2iDialect problem with supportsRowValueConstructorSyntaxInInSubQuery * HHH-19855 at entity level is ignored in orm.xml * HHH-19075 SqmFunction.appendHqlString(…) fails with IndexOutOfBoundsException for trim rendering

** Improvement * HHH-3192 SchemaValidator nullability check

Changes in 7.2.0.Final (December 12, 2025)

https://hibernate.atlassian.net/projects/HHH/versions/36806

Changes in 7.2.0.CR4 (December 10, 2025)

... (truncated)

Commits
  • 097f0f5 [Jenkins release job] Preparing release 7.2.2.Final
  • 8f48c23 [Jenkins release job] changelog.txt updated by release build 7.2.2.Final
  • 1161f12 HHH-20095 Revert "HHH-3192 - SchemaValidator column nullability check"
  • 10ec66a HHH-19999 migrate to Comparator<Object> in the caching APIs
  • b6a1de4 HHH-20087 Check if source is not null before converting it in AbstractSession...
  • 2707480 HHH-19823, HHH-19822 add to what's new
  • 2f03b55 HHH-20069 Remove usage of non-existing rowid_ column on DB2 for i and z/OS
  • b1f490e HHH-19192 prevent physically deleting collections when soft delete is set
  • a5a189a HHH-18835 Use multi-table insert also for generators that don't support bulk ...
  • 178d0e3 HHH-18835 Test AssertionError for insert-select with table sequence
  • Additional commits viewable in compare view

Dependabot compatibility score

Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting @dependabot rebase.


Dependabot commands and options

You can trigger Dependabot actions by commenting on this PR:

  • @dependabot rebase will rebase this PR
  • @dependabot recreate will recreate this PR, overwriting any edits that have been made to it
  • @dependabot merge will merge this PR after your CI passes on it
  • @dependabot squash and merge will squash and merge this PR after your CI passes on it
  • @dependabot cancel merge will cancel a previously requested merge and block automerging
  • @dependabot reopen will reopen this PR if it is closed
  • @dependabot close will close this PR and stop Dependabot recreating it. You can achieve the same result by closing it manually
  • @dependabot show <dependency name> ignore conditions will show all of the ignore conditions of the specified dependency
  • @dependabot ignore this major version will close this PR and stop Dependabot creating any more for this major version (unless you reopen the PR or upgrade to it yourself)
  • @dependabot ignore this minor version will close this PR and stop Dependabot creating any more for this minor version (unless you reopen the PR or upgrade to it yourself)
  • @dependabot ignore this dependency will close this PR and stop Dependabot creating any more for this dependency (unless you reopen the PR or upgrade to it yourself)

Bumps [org.hibernate:hibernate-core](https://github.com/hibernate/hibernate-orm) from 6.6.13.Final to 7.2.2.Final.
- [Release notes](https://github.com/hibernate/hibernate-orm/releases)
- [Changelog](https://github.com/hibernate/hibernate-orm/blob/7.2.2/changelog.txt)
- [Commits](hibernate/hibernate-orm@6.6.13...7.2.2)

---
updated-dependencies:
- dependency-name: org.hibernate:hibernate-core
  dependency-version: 7.2.2.Final
  dependency-type: direct:production
  update-type: version-update:semver-major
...

Signed-off-by: dependabot[bot] <support@github.com>
@dependabot dependabot Bot added dependencies Pull requests that update a dependency file java Pull requests that update java code labels Jan 29, 2026
@dependabot dependabot Bot requested a review from a team as a code owner January 29, 2026 18:31
@dependabot dependabot Bot added dependencies Pull requests that update a dependency file java Pull requests that update java code labels Jan 29, 2026

@danielfrankcom danielfrankcom left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

This should not be merged until the pom.xml is updated equivalently. The test workflows are passing because they use the Maven dependencies, not Gradle. We wouldn't want to merge this change as it would break the example for customers using Gradle.

It is not possible to upgrade this right now due to API differences between the v6 and v7 major versions.

@dependabot @github

dependabot Bot commented on behalf of github Feb 2, 2026

Copy link
Copy Markdown
Contributor Author

Superseded by #83.

@dependabot dependabot Bot closed this Feb 2, 2026
@dependabot dependabot Bot deleted the dependabot/gradle/java/hibernate/examples/pet-clinic-app/org.hibernate-hibernate-core-7.2.2.Final branch February 2, 2026 01:20
amaksimo added a commit that referenced this pull request Feb 28, 2026
Security fixes:
- Bump hono override from ^4.11.7 to ^4.11.10 (timing comparison
  hardening in basicAuth/bearerAuth, alerts #18 and #19)
- Add fast-xml-parser ^5.4.1 override to node/prisma (stack overflow
  in XMLBuilder, alert #32)
- Bump fast-xml-parser override in veterinary-app from ^5.3.4 to
  ^5.4.1 for consistency

Dependabot improvement:
- Use directories (plural) for node/prisma so the connector and its
  veterinary-app example are updated in the same PR, keeping
  lockfiles consistent.
amaksimo added a commit that referenced this pull request Feb 28, 2026
…abot config (#300)

## Summary

Resolves all 3 open Dependabot security alerts and fixes a systemic
Dependabot config issue.

## Security Alerts Fixed

| Severity | Alert | Package | Location | Fix |
|----------|-------|---------|----------|-----|
| LOW | #32 | fast-xml-parser < 5.3.8 | node/prisma | Added override
^5.4.1 |
| LOW | #19 | hono < 4.11.10 | node/prisma | Bumped override ^4.11.7 →
^4.11.10 |
| LOW | #18 | hono < 4.11.10 | node/prisma/examples/veterinary-app |
Bumped override ^4.11.7 → ^4.11.10 |

The existing overrides had version ranges that were too low to cover the
required fix versions.

## Dependabot Config Fix

Changed `node/prisma` and `node/prisma/examples/veterinary-app` from
separate `directory` entries to a single entry using `directories`
(plural). This ensures both lockfiles are updated in the same PR,
keeping dependencies consistent between the library and its example.

## Test plan

- [x] `npm audit` reports 0 vulnerabilities in both directories
- [ ] CI passes
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

dependencies Pull requests that update a dependency file java Pull requests that update java code

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant