Bump org.hibernate:hibernate-core from 6.6.13.Final to 7.2.2.Final in /java/hibernate/examples/pet-clinic-app#32
Closed
dependabot[bot] wants to merge 1 commit into
Conversation
Bumps [org.hibernate:hibernate-core](https://github.com/hibernate/hibernate-orm) from 6.6.13.Final to 7.2.2.Final. - [Release notes](https://github.com/hibernate/hibernate-orm/releases) - [Changelog](https://github.com/hibernate/hibernate-orm/blob/7.2.2/changelog.txt) - [Commits](hibernate/hibernate-orm@6.6.13...7.2.2) --- updated-dependencies: - dependency-name: org.hibernate:hibernate-core dependency-version: 7.2.2.Final dependency-type: direct:production update-type: version-update:semver-major ... Signed-off-by: dependabot[bot] <support@github.com>
danielfrankcom
suggested changes
Jan 30, 2026
danielfrankcom
left a comment
Contributor
There was a problem hiding this comment.
This should not be merged until the pom.xml is updated equivalently. The test workflows are passing because they use the Maven dependencies, not Gradle. We wouldn't want to merge this change as it would break the example for customers using Gradle.
It is not possible to upgrade this right now due to API differences between the v6 and v7 major versions.
Contributor
Author
|
Superseded by #83. |
amaksimo
added a commit
that referenced
this pull request
Feb 28, 2026
Security fixes: - Bump hono override from ^4.11.7 to ^4.11.10 (timing comparison hardening in basicAuth/bearerAuth, alerts #18 and #19) - Add fast-xml-parser ^5.4.1 override to node/prisma (stack overflow in XMLBuilder, alert #32) - Bump fast-xml-parser override in veterinary-app from ^5.3.4 to ^5.4.1 for consistency Dependabot improvement: - Use directories (plural) for node/prisma so the connector and its veterinary-app example are updated in the same PR, keeping lockfiles consistent.
2 tasks
amaksimo
added a commit
that referenced
this pull request
Feb 28, 2026
…abot config (#300) ## Summary Resolves all 3 open Dependabot security alerts and fixes a systemic Dependabot config issue. ## Security Alerts Fixed | Severity | Alert | Package | Location | Fix | |----------|-------|---------|----------|-----| | LOW | #32 | fast-xml-parser < 5.3.8 | node/prisma | Added override ^5.4.1 | | LOW | #19 | hono < 4.11.10 | node/prisma | Bumped override ^4.11.7 → ^4.11.10 | | LOW | #18 | hono < 4.11.10 | node/prisma/examples/veterinary-app | Bumped override ^4.11.7 → ^4.11.10 | The existing overrides had version ranges that were too low to cover the required fix versions. ## Dependabot Config Fix Changed `node/prisma` and `node/prisma/examples/veterinary-app` from separate `directory` entries to a single entry using `directories` (plural). This ensures both lockfiles are updated in the same PR, keeping dependencies consistent between the library and its example. ## Test plan - [x] `npm audit` reports 0 vulnerabilities in both directories - [ ] CI passes
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Bumps org.hibernate:hibernate-core from 6.6.13.Final to 7.2.2.Final.
Release notes
Sourced from org.hibernate:hibernate-core's releases.
... (truncated)
Changelog
Sourced from org.hibernate:hibernate-core's changelog.
... (truncated)
Commits
097f0f5[Jenkins release job] Preparing release 7.2.2.Final8f48c23[Jenkins release job] changelog.txt updated by release build 7.2.2.Final1161f12HHH-20095 Revert "HHH-3192 - SchemaValidator column nullability check"10ec66aHHH-19999 migrate to Comparator<Object> in the caching APIsb6a1de4HHH-20087 Check if source is not null before converting it in AbstractSession...2707480HHH-19823, HHH-19822 add to what's new2f03b55HHH-20069 Remove usage of non-existing rowid_ column on DB2 for i and z/OSb1f490eHHH-19192 prevent physically deleting collections when soft delete is seta5a189aHHH-18835 Use multi-table insert also for generators that don't support bulk ...178d0e3HHH-18835 Test AssertionError for insert-select with table sequenceDependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting
@dependabot rebase.Dependabot commands and options
You can trigger Dependabot actions by commenting on this PR:
@dependabot rebasewill rebase this PR@dependabot recreatewill recreate this PR, overwriting any edits that have been made to it@dependabot mergewill merge this PR after your CI passes on it@dependabot squash and mergewill squash and merge this PR after your CI passes on it@dependabot cancel mergewill cancel a previously requested merge and block automerging@dependabot reopenwill reopen this PR if it is closed@dependabot closewill close this PR and stop Dependabot recreating it. You can achieve the same result by closing it manually@dependabot show <dependency name> ignore conditionswill show all of the ignore conditions of the specified dependency@dependabot ignore this major versionwill close this PR and stop Dependabot creating any more for this major version (unless you reopen the PR or upgrade to it yourself)@dependabot ignore this minor versionwill close this PR and stop Dependabot creating any more for this minor version (unless you reopen the PR or upgrade to it yourself)@dependabot ignore this dependencywill close this PR and stop Dependabot creating any more for this dependency (unless you reopen the PR or upgrade to it yourself)