Skip to content

Bump com.microsoft.sqlserver:mssql-jdbc from 12.8.1.jre11 to 12.10.2.jre11#3528

Merged
spring-builds merged 1 commit intomainfrom
dependabot/gradle/main/com.microsoft.sqlserver-mssql-jdbc-12.10.2.jre11
Dec 15, 2025
Merged

Bump com.microsoft.sqlserver:mssql-jdbc from 12.8.1.jre11 to 12.10.2.jre11#3528
spring-builds merged 1 commit intomainfrom
dependabot/gradle/main/com.microsoft.sqlserver-mssql-jdbc-12.10.2.jre11

Conversation

@dependabot
Copy link
Copy Markdown
Contributor

@dependabot dependabot bot commented on behalf of github Dec 15, 2025

Bumps com.microsoft.sqlserver:mssql-jdbc from 12.8.1.jre11 to 12.10.2.jre11.

Release notes

Sourced from com.microsoft.sqlserver:mssql-jdbc's releases.

[12.8.2] Hotfix & Stable Release

Fixed issues

  • Address a hostname validation vulnerability by securely parsing certificate common names. microsoft/mssql-jdbc#2804 What was fixed: Secure hostname validation is enforced by replacing the vulnerable CN parsing logic in SQLServerCertificateUtils.java, preventing spoofing attacks. Who benefits: All users of the SQL Server JDBC driver, especially those relying on TLS for secure connections, benefit from improved certificate validation.

[12.10.1] Stable Release

Fixed issues

  • Make ibm security module optional #2679
  • Invalidate existing enclave session during connection (re)connect #2680
  • Update readFromFile() in ConfigurableRetryLogic to handle filePath #2681
  • Increased the max noOfRedirections and updated the message. #2682
  • Fixed New Type Param Definitions logic in doExecutePreparedStatement #2683
  • Fixed session recovery for Azure SQL DB in redirect mode connected #2684

[12.10.0] Stable Release

Added

  • Added provision to set SQLServerBulkCopy options in PreparedStatement #2555

Changed

  • Changed the scope of BULK_COPY_OPERATION_CACHE to connection #2594
  • Added "requireSecret" exclude tag for tests which require adding a secret to app registration #2596
  • Added com.ibm.security.auth.module and com.sun.security.auth.module as option import #2609
  • Updated driver dependency versions #2614

Fixed issues

  • Introduced timeouts for MSAL calls #2562
  • Fixed getGeneratedKeys functionality for execute API #2554
  • Fixed ISQLServerConnection java doc reference #2560
  • Fixed OffsetDateTime conversion for pre-Gregorian dates #2568
  • Fix for driver cutting out the question mark from columns labels (aliases) #2569
  • Fixed issue with SQLServerBulkCopy from CSV with setEscapeColumnDelimerts set to true #2575
  • Fixed issue for finding mssql-jdbc.properties location in test environments #2579
  • Fixed issue for IBM Semeru Runtime Certified Edition for z/OS and Kerberos #2581
  • Set appropriate value to requestedEncryptionLevel for encrypt=STRICT #2597
  • Add test for ManagedIdentityWithEncryptStrict #2599
  • Check for null when getting DTV values (JDBC spec compliance - getBinaryStream /getAsciiStream will return null when the value is null) #2600
  • Removed scheme from URI before fetching path for CRL path check #2622

[12.9.0] Preview Release

Added

  • Added configurable retry logic feature, supporting both statement, and connection, retry #2396#2519
  • Added JDK 23 support #2515

Changed

  • Reverted "Execute Stored Procedures Directly" feature, as well as subsequent changes related to the feature #2488
  • Changed MSAL logging from FINEST to FINER #2489
  • Updated project pom file to pull dependencies from public Azure Artifacts Feed #2504
  • Changed how Kerberos authentication acquires subject to provide compatibility for Kerberos with Java 23 and above #2539
  • Removed user and password check for AccessTokenCallback #2549

Fixed issues

... (truncated)

Commits

Dependabot compatibility score

Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting @dependabot rebase.


Dependabot commands and options

You can trigger Dependabot actions by commenting on this PR:

  • @dependabot rebase will rebase this PR
  • @dependabot recreate will recreate this PR, overwriting any edits that have been made to it
  • @dependabot merge will merge this PR after your CI passes on it
  • @dependabot squash and merge will squash and merge this PR after your CI passes on it
  • @dependabot cancel merge will cancel a previously requested merge and block automerging
  • @dependabot reopen will reopen this PR if it is closed
  • @dependabot close will close this PR and stop Dependabot recreating it. You can achieve the same result by closing it manually
  • @dependabot show <dependency name> ignore conditions will show all of the ignore conditions of the specified dependency
  • @dependabot ignore this major version will close this PR and stop Dependabot creating any more for this major version (unless you reopen the PR or upgrade to it yourself)
  • @dependabot ignore this minor version will close this PR and stop Dependabot creating any more for this minor version (unless you reopen the PR or upgrade to it yourself)
  • @dependabot ignore this dependency will close this PR and stop Dependabot creating any more for this dependency (unless you reopen the PR or upgrade to it yourself)

@dependabot dependabot bot added the type: dependency-upgrade A dependency upgrade label Dec 15, 2025
@github-actions github-actions bot added this to the 4.0.1 milestone Dec 15, 2025
@spring-builds spring-builds enabled auto-merge (rebase) December 15, 2025 22:20
@dependabot dependabot bot force-pushed the dependabot/gradle/main/com.microsoft.sqlserver-mssql-jdbc-12.10.2.jre11 branch 3 times, most recently from 9a38b7b to a2e378d Compare December 15, 2025 22:31
Bumps [com.microsoft.sqlserver:mssql-jdbc](https://github.com/Microsoft/mssql-jdbc) from 12.8.1.jre11 to 12.10.2.jre11.
- [Release notes](https://github.com/Microsoft/mssql-jdbc/releases)
- [Changelog](https://github.com/microsoft/mssql-jdbc/blob/main/CHANGELOG.md)
- [Commits](https://github.com/Microsoft/mssql-jdbc/commits)

---
updated-dependencies:
- dependency-name: com.microsoft.sqlserver:mssql-jdbc
  dependency-version: 12.10.2.jre11
  dependency-type: direct:production
  update-type: version-update:semver-minor
...

Signed-off-by: dependabot[bot] <support@github.com>
@dependabot dependabot bot force-pushed the dependabot/gradle/main/com.microsoft.sqlserver-mssql-jdbc-12.10.2.jre11 branch from a2e378d to 462d633 Compare December 15, 2025 22:41
@spring-builds spring-builds merged commit f5040da into main Dec 15, 2025
5 checks passed
@dependabot dependabot bot deleted the dependabot/gradle/main/com.microsoft.sqlserver-mssql-jdbc-12.10.2.jre11 branch December 15, 2025 22:48
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

type: dependency-upgrade A dependency upgrade

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant