Skip to content

Bump org.apache.logging.log4j:log4j-core from 2.25.2 to 2.25.3 in /buildSrc/src/testKit/thirdPartyAudit/sample_jars#20300

Merged
cwperks merged 5 commits intomainfrom
dependabot/gradle/buildSrc/src/testKit/thirdPartyAudit/sample_jars/org.apache.logging.log4j-log4j-core-2.25.3
Dec 22, 2025
Merged

Bump org.apache.logging.log4j:log4j-core from 2.25.2 to 2.25.3 in /buildSrc/src/testKit/thirdPartyAudit/sample_jars#20300
cwperks merged 5 commits intomainfrom
dependabot/gradle/buildSrc/src/testKit/thirdPartyAudit/sample_jars/org.apache.logging.log4j-log4j-core-2.25.3

Conversation

@dependabot
Copy link
Copy Markdown
Contributor

@dependabot dependabot bot commented on behalf of github Dec 22, 2025

Bumps org.apache.logging.log4j:log4j-core from 2.25.2 to 2.25.3.

Dependabot compatibility score

Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting @dependabot rebase.


Dependabot commands and options

You can trigger Dependabot actions by commenting on this PR:

  • @dependabot rebase will rebase this PR
  • @dependabot recreate will recreate this PR, overwriting any edits that have been made to it
  • @dependabot merge will merge this PR after your CI passes on it
  • @dependabot squash and merge will squash and merge this PR after your CI passes on it
  • @dependabot cancel merge will cancel a previously requested merge and block automerging
  • @dependabot reopen will reopen this PR if it is closed
  • @dependabot close will close this PR and stop Dependabot recreating it. You can achieve the same result by closing it manually
  • @dependabot show <dependency name> ignore conditions will show all of the ignore conditions of the specified dependency
  • @dependabot ignore this major version will close this PR and stop Dependabot creating any more for this major version (unless you reopen the PR or upgrade to it yourself)
  • @dependabot ignore this minor version will close this PR and stop Dependabot creating any more for this minor version (unless you reopen the PR or upgrade to it yourself)
  • @dependabot ignore this dependency will close this PR and stop Dependabot creating any more for this dependency (unless you reopen the PR or upgrade to it yourself)

Summary by CodeRabbit

  • Chores
    • Bumped log4j-core dependency from 2.25.2 to 2.25.3 in build configuration.
    • Added changelog entry documenting the dependency update. No changes to public APIs or runtime behavior; low review effort.

✏️ Tip: You can customize this high-level summary in your review settings.

Bumps org.apache.logging.log4j:log4j-core from 2.25.2 to 2.25.3.

---
updated-dependencies:
- dependency-name: org.apache.logging.log4j:log4j-core
  dependency-version: 2.25.3
  dependency-type: direct:production
  update-type: version-update:semver-patch
...

Signed-off-by: dependabot[bot] <support@github.com>
@dependabot dependabot bot added dependabot PRs with auto version bumps from dependabot dependencies Pull requests that update a dependency file patch labels Dec 22, 2025
@dependabot dependabot bot requested a review from a team as a code owner December 22, 2025 13:01
@dependabot dependabot bot added the dependabot PRs with auto version bumps from dependabot label Dec 22, 2025
@coderabbitai
Copy link
Copy Markdown
Contributor

coderabbitai bot commented Dec 22, 2025

Walkthrough

Bump org.apache.logging.log4j:log4j-core from 2.25.2 to 2.25.3 in the Gradle build for third-party-audit sample jars and add a matching entry to CHANGELOG.md. No codeflow or public API changes.

Changes

Cohort / File(s) Summary
Dependency Update
buildSrc/src/testKit/thirdPartyAudit/sample_jars/build.gradle
Upgrade org.apache.logging.log4j:log4j-core 2.25.2 → 2.25.3
Changelog
CHANGELOG.md
Add entry noting bump of org.apache.logging.log4j:log4j-core 2.25.2 → 2.25.3

Estimated code review effort

🎯 1 (Trivial) | ⏱️ ~2 minutes

  • Review focus: confirm the single dependency coordinate change and the corresponding changelog entry.

Suggested reviewers

  • jed326

Poem

🐰 I hopped a patch, a tiny spree,
From two-two-five to two-two-three,
A gentle hop, the build stayed calm,
I nibble code and hold my charm,
Commit done — a carrot-crumbed glee 🥕

Pre-merge checks and finishing touches

❌ Failed checks (1 warning)
Check name Status Explanation Resolution
Description check ⚠️ Warning The PR description lacks required template sections (Description, Related Issues, Check List) and does not explain what this change achieves or provide proper context. Add a proper Description section explaining the purpose of the bump, and complete the Related Issues and Check List sections from the template.
✅ Passed checks (2 passed)
Check name Status Explanation
Title check ✅ Passed The title clearly and specifically describes the main change: bumping log4j-core from 2.25.2 to 2.25.3 in a specific path.
Docstring Coverage ✅ Passed No functions found in the changed files to evaluate docstring coverage. Skipping docstring coverage check.
✨ Finishing touches
🧪 Generate unit tests (beta)
  • Create PR with unit tests
  • Post copyable unit tests in a comment
  • Commit unit tests in branch dependabot/gradle/buildSrc/src/testKit/thirdPartyAudit/sample_jars/org.apache.logging.log4j-log4j-core-2.25.3

📜 Recent review details

Configuration used: defaults

Review profile: CHILL

Plan: Pro

📥 Commits

Reviewing files that changed from the base of the PR and between c731c27 and 0022fee.

📒 Files selected for processing (1)
  • CHANGELOG.md
🚧 Files skipped from review as they are similar to previous changes (1)
  • CHANGELOG.md
⏰ Context from checks skipped due to timeout of 90000ms. You can increase the timeout in your CodeRabbit configuration to a maximum of 15 minutes (900000ms). (21)
  • GitHub Check: gradle-check
  • GitHub Check: assemble (21, ubuntu-24.04-arm)
  • GitHub Check: assemble (25, ubuntu-latest)
  • GitHub Check: precommit (25, macos-15)
  • GitHub Check: assemble (25, windows-latest)
  • GitHub Check: assemble (21, windows-latest)
  • GitHub Check: precommit (25, macos-15-intel)
  • GitHub Check: precommit (21, windows-latest)
  • GitHub Check: assemble (21, ubuntu-latest)
  • GitHub Check: precommit (25, ubuntu-latest)
  • GitHub Check: precommit (21, macos-15)
  • GitHub Check: precommit (21, windows-2025, true)
  • GitHub Check: detect-breaking-change
  • GitHub Check: precommit (25, windows-latest)
  • GitHub Check: assemble (25, ubuntu-24.04-arm)
  • GitHub Check: precommit (21, ubuntu-24.04-arm)
  • GitHub Check: precommit (25, ubuntu-24.04-arm)
  • GitHub Check: precommit (21, ubuntu-latest)
  • GitHub Check: precommit (21, macos-15-intel)
  • GitHub Check: Analyze (java)
  • GitHub Check: dependabot

Comment @coderabbitai help to get the list of available commands and usage tips.

dependabot bot and others added 2 commits December 22, 2025 13:05
Signed-off-by: dependabot[bot] <support@github.com>
…PartyAudit/sample_jars/org.apache.logging.log4j-log4j-core-2.25.3

Signed-off-by: Craig Perkins <cwperx@amazon.com>
@github-actions
Copy link
Copy Markdown
Contributor

✅ Gradle check result for 3567811: SUCCESS

@codecov
Copy link
Copy Markdown

codecov bot commented Dec 22, 2025

Codecov Report

✅ All modified and coverable lines are covered by tests.
✅ Project coverage is 73.27%. Comparing base (be07784) to head (0022fee).
⚠️ Report is 2 commits behind head on main.

Additional details and impacted files
@@             Coverage Diff              @@
##               main   #20300      +/-   ##
============================================
+ Coverage     73.16%   73.27%   +0.10%     
- Complexity    71744    71774      +30     
============================================
  Files          5795     5795              
  Lines        328304   328304              
  Branches      47281    47281              
============================================
+ Hits         240216   240574     +358     
+ Misses        68822    68404     -418     
- Partials      19266    19326      +60     

☔ View full report in Codecov by Sentry.
📢 Have feedback on the report? Share it here.

🚀 New features to boost your workflow:
  • ❄️ Test Analytics: Detect flaky tests, report on failures, and find test suite problems.

…PartyAudit/sample_jars/org.apache.logging.log4j-log4j-core-2.25.3

Signed-off-by: Craig Perkins <cwperx@amazon.com>
@github-actions
Copy link
Copy Markdown
Contributor

❕ Gradle check result for c731c27: UNSTABLE

Please review all flaky tests that succeeded after retry and create an issue if one does not already exist to track the flaky failure.

…PartyAudit/sample_jars/org.apache.logging.log4j-log4j-core-2.25.3

Signed-off-by: Craig Perkins <cwperx@amazon.com>
@github-actions
Copy link
Copy Markdown
Contributor

✅ Gradle check result for 0022fee: SUCCESS

@cwperks cwperks merged commit 1ebe587 into main Dec 22, 2025
35 checks passed
@dependabot dependabot bot deleted the dependabot/gradle/buildSrc/src/testKit/thirdPartyAudit/sample_jars/org.apache.logging.log4j-log4j-core-2.25.3 branch December 22, 2025 22:08
mohit10011999 pushed a commit to mohit10011999/OpenSearch that referenced this pull request Dec 30, 2025
…ildSrc/src/testKit/thirdPartyAudit/sample_jars (opensearch-project#20300)

* Bump org.apache.logging.log4j:log4j-core

Bumps org.apache.logging.log4j:log4j-core from 2.25.2 to 2.25.3.

---
updated-dependencies:
- dependency-name: org.apache.logging.log4j:log4j-core
  dependency-version: 2.25.3
  dependency-type: direct:production
  update-type: version-update:semver-patch
...

Signed-off-by: dependabot[bot] <support@github.com>

* Update changelog

Signed-off-by: dependabot[bot] <support@github.com>

---------

Signed-off-by: dependabot[bot] <support@github.com>
Signed-off-by: Craig Perkins <cwperx@amazon.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
Co-authored-by: Craig Perkins <cwperx@amazon.com>
mohit10011999 pushed a commit to mohit10011999/OpenSearch that referenced this pull request Dec 30, 2025
…ildSrc/src/testKit/thirdPartyAudit/sample_jars (opensearch-project#20300)

* Bump org.apache.logging.log4j:log4j-core

Bumps org.apache.logging.log4j:log4j-core from 2.25.2 to 2.25.3.

---
updated-dependencies:
- dependency-name: org.apache.logging.log4j:log4j-core
  dependency-version: 2.25.3
  dependency-type: direct:production
  update-type: version-update:semver-patch
...

Signed-off-by: dependabot[bot] <support@github.com>

* Update changelog

Signed-off-by: dependabot[bot] <support@github.com>

---------

Signed-off-by: dependabot[bot] <support@github.com>
Signed-off-by: Craig Perkins <cwperx@amazon.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
Co-authored-by: Craig Perkins <cwperx@amazon.com>
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

dependabot PRs with auto version bumps from dependabot dependencies Pull requests that update a dependency file patch

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant