Skip to content

WFLY-21392 Bump org.assertj:assertj-bom from 3.27.6 to 3.27.7#19555

Merged
rhusar merged 1 commit intomainfrom
dependabot/maven/org.assertj-assertj-bom-3.27.7
Jan 27, 2026
Merged

WFLY-21392 Bump org.assertj:assertj-bom from 3.27.6 to 3.27.7#19555
rhusar merged 1 commit intomainfrom
dependabot/maven/org.assertj-assertj-bom-3.27.7

Conversation

@dependabot
Copy link
Contributor

@dependabot dependabot bot commented on behalf of github Jan 26, 2026

Resolves
https://issues.redhat.com/browse/WFLY-21392

Bumps org.assertj:assertj-bom from 3.27.6 to 3.27.7.

Release notes

Sourced from org.assertj:assertj-bom's releases.

v3.27.7

🔒 Security

Core

🚫 Deprecated

Core

  • Deprecate XmlStringPrettyFormatter with no replacement

🐛 Bug Fixes

Guava

  • Navigation to assertj-core or guava types from assertj-guava Javadoc site has unnecessary header #3478

🔨 Dependency Upgrades

Core

  • Upgrade to Byte Buddy 1.18.3
  • Upgrade to JUnit BOM 5.14.1

Guava

  • Upgrade to Guava 33.5.0-jre
Commits
  • e840716 [maven-release-plugin] prepare release assertj-build-3.27.7
  • 85ca7eb Deprecate XmlStringPrettyFormatter
  • 77081dc Merge commit from fork
  • b68fc24 Bump github/codeql-action from 4.31.9 to 4.31.10 in the github-actions group ...
  • 0cf5bb6 Bump kotlin.version from 2.1.0 to 2.2.21
  • d393ef1 Abort tests when symbolic links cannot be created (#3788)
  • 2212433 Add IntelliJ custom inspection for test class names
  • 5717d02 Update JetBrains icon
  • a8ec20b Add icon for JetBrains products
  • c05fb3d Bump Maven to 3.9.12 and Wrapper to 3.3.4
  • Additional commits viewable in compare view

Dependabot compatibility score

You can trigger a rebase of this PR by commenting @dependabot rebase.


Dependabot commands and options

You can trigger Dependabot actions by commenting on this PR:

  • @dependabot rebase will rebase this PR
  • @dependabot recreate will recreate this PR, overwriting any edits that have been made to it
  • @dependabot merge will merge this PR after your CI passes on it
  • @dependabot squash and merge will squash and merge this PR after your CI passes on it
  • @dependabot cancel merge will cancel a previously requested merge and block automerging
  • @dependabot reopen will reopen this PR if it is closed
  • @dependabot close will close this PR and stop Dependabot recreating it. You can achieve the same result by closing it manually
  • @dependabot show <dependency name> ignore conditions will show all of the ignore conditions of the specified dependency
  • @dependabot ignore this major version will close this PR and stop Dependabot creating any more for this major version (unless you reopen the PR or upgrade to it yourself)
  • @dependabot ignore this minor version will close this PR and stop Dependabot creating any more for this minor version (unless you reopen the PR or upgrade to it yourself)
  • @dependabot ignore this dependency will close this PR and stop Dependabot creating any more for this dependency (unless you reopen the PR or upgrade to it yourself)

Bumps [org.assertj:assertj-bom](https://github.com/assertj/assertj) from 3.27.6 to 3.27.7.
- [Release notes](https://github.com/assertj/assertj/releases)
- [Commits](assertj/assertj@assertj-build-3.27.6...assertj-build-3.27.7)

---
updated-dependencies:
- dependency-name: org.assertj:assertj-bom
  dependency-version: 3.27.7
  dependency-type: direct:production
  update-type: version-update:semver-patch
...

Signed-off-by: dependabot[bot] <support@github.com>
@dependabot dependabot bot added dependencies Added by dependabot to pull requests that update a dependency file java Pull requests that update Java code. Typically added by dependabot. labels Jan 26, 2026
@wildfly-bot
Copy link

wildfly-bot bot commented Jan 26, 2026

WildFly Bot recognized this PR as dependabot dependency update. Please create a WFLY issue and add new comment containing this JIRA link please.

@github-actions github-actions bot added the deps-ok Dependencies have been checked, and there are no significant changes label Jan 26, 2026
@rhusar
Copy link
Member

rhusar commented Jan 27, 2026

Fixes a CVE - fix for CVE-2026-24400. Opened Jira to track fix of the CVE - https://issues.redhat.com/browse/WFLY-21392

@rhusar rhusar changed the title Bump org.assertj:assertj-bom from 3.27.6 to 3.27.7 WFLY-21392 Bump org.assertj:assertj-bom from 3.27.6 to 3.27.7 Jan 27, 2026
@rhusar rhusar merged commit 4895e00 into main Jan 27, 2026
13 of 16 checks passed
@rhusar rhusar deleted the dependabot/maven/org.assertj-assertj-bom-3.27.7 branch January 27, 2026 10:57
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

dependencies Added by dependabot to pull requests that update a dependency file deps-ok Dependencies have been checked, and there are no significant changes java Pull requests that update Java code. Typically added by dependabot.

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant