dependabot[bot] opened a new pull request, #27061: URL: https://github.com/apache/camel/pull/27061
Bumps [io.github.classgraph:classgraph](https://github.com/classgraph/classgraph) from 4.8.195 to 4.8.196. <details> <summary>Release notes</summary> <p><em>Sourced from <a href="https://github.com/classgraph/classgraph/releases">io.github.classgraph:classgraph's releases</a>.</em></p> <blockquote> <h2>ClassGraph 4.8.196</h2> <p><strong>ClassGraph 5.0.0 is coming shortly</strong>, and requires JDK 17 or newer. 4.8.196 is a bugfix release on the 4.x maintenance branch, and continues the file-by-file audit that produced 4.8.190 through 4.8.195. As before, most of the bugs listed here were found by Claude through careful code analysis, and were fixed on the v5 branch and backported to v4.</p> <h2>Mocking the list classes with mockk works again (<a href="https://redirect.github.com/classgraph/classgraph/issues/945">#945</a>)</h2> <p>Since 4.8.185, mockk failed to mock <code>ResourceList</code>, <code>ClassInfoList</code> and the other list classes, with "class redefinition failed: attempted to add a method". These classes extend a package-private class, and releases since 4.8.185 were built with JDK 8, whose javac does not emit public bridge methods in the public subclass for <code>add(T)</code>, <code>add(int, T)</code>, <code>remove(int)</code> and <code>set(int, T)</code>. The list classes now declare these methods themselves, so they are present whichever JDK builds the release.</p> <h2>Bug fixes: classpath elements and jarfiles</h2> <ul> <li> <p><strong>The context classloader could be moved behind the application classloader.</strong> The classloaders found in the environment were sorted by descending delegation depth, so that a classloader is searched before its ancestors. That also put any classloader with more ancestors ahead of an unrelated one with fewer -- the application classloader ahead of a context classloader with no parent, for example -- although the context classloader is meant to be tried first. Each classloader is now inserted just ahead of the first of its ancestors that is already listed, which keeps descendants ahead of ancestors and otherwise keeps the preference order.</p> </li> <li> <p><strong><code>Class-Path</code> and <code>Bundle-ClassPath</code> manifest attributes are now read with their specified syntax.</strong> A <code>Class-Path</code> entry is a relative URL, so its percent encoding is now decoded, as the JVM's own classloader decodes it. Before, a jarfile written as <code>my%20lib.jar</code> was looked for under that literal name, so a jarfile with a space in its name could not be named at all. <code>Bundle-ClassPath</code> paths are now trimmed, unquoted and separated from their parameters, following the OSGi header syntax. Before, <code>. , inner.jar</code> named <code> inner.jar</code>, and a quoted path or one with a parameter named nothing that exists.</p> </li> <li> <p><strong>When a zipfile has two entries with the same name, the last one is now used, as the JDK does.</strong> ClassGraph kept the first, so a scan could report a different resource, and open a different nested jarfile, than the JVM would load.</p> </li> <li> <p><strong><code>META-INF/versions/09/</code> is no longer read as multi-release version 9.</strong> The JDK looks up versioned entries only under the plain decimal version number, so ClassGraph could report a class that the JVM never loads.</p> </li> <li> <p><strong>The file of a nested jarfile is now always the outermost jarfile.</strong> It was the outer jarfile if the nested jarfile was stored, but null or a temporary file if it was deflated. <code>ScanResult#getClasspathFiles()</code> lists the outer jarfile once, however many jarfiles are nested within it.</p> </li> <li> <p><strong>A zipfile with an Info-ZIP Unicode path extra field of a version other than 1 could not be read.</strong> <code>java.util.zip.ZipFile</code> opens such a file, since the JDK does not read that field. The field is now logged and ignored.</p> </li> <li> <p><strong>A large nested jar with a long name could not be opened.</strong> A nested jar too large to hold in RAM is written to a temporary file named after its zip entry, and a long entry name made <code>File.createTempFile</code> fail with "File name too long". The name is now cut to its last 64 characters.</p> </li> <li> <p><strong>A jarfile URL that redirected from http to https failed</strong> with "Got response code 301", since <code>HttpURLConnection</code> only follows a redirect that keeps the same scheme. Redirects are now followed, up to 20 times. A redirect from https to http, or to a scheme that has not been enabled, is refused.</p> </li> <li> <p><strong>A <code>SecurityManager</code> that refused to let ClassGraph read a file's attributes stopped the scan of the rest of that directory.</strong> Only that file is now skipped.</p> </li> <li> <p><strong>The Quarkus classloader handler failed the whole scan</strong> when a field it reads held a null or unexpected value. Such elements are now skipped.</p> </li> <li> <p><strong><code>normalizePath</code> did not collapse <code>//</code> in a path that did not end with a separator,</strong> so <code>a//b</code> stayed <code>a//b</code> while <code>a//b/</code> became <code>a/b</code>.</p> </li> </ul> <h2>Bug fixes: memory, file handles and temporary files</h2> <ul> <li> <p><strong>A file is no longer memory-mapped when it could not be unmapped again.</strong> A <code>SecurityManager</code> that denied access to the buffer cleaner made <code>new ClassGraph()</code> throw "Cannot get buffer cleaner method". Now, below JDK 22, a file is only memory-mapped when the cleaner is available, since otherwise the mapping, and on Windows the file lock, would last until the buffer was garbage collected.</p> </li> <li> <p><strong>A canceled <code>scanAsync</code> future leaked its <code>ScanResult</code>.</strong> A result that arrived after the future was canceled was never handed to anyone, so nothing closed it. It is now closed. The call stack and context classloader are still read on the calling thread, but the jarfiles are now opened when the task runs, so a task that is canceled before it starts opens nothing.</p> </li> <li> <p><strong>Temporary files no longer use <code>deleteOnExit()</code>.</strong> Closing the scan already deletes every temporary file, so <code>deleteOnExit()</code> only made the JDK hold every temporary path until the JVM exited.</p> </li> <li> <p><strong>A module reader could be left open</strong> if it was returned to its pool at the same moment the pool was being force-closed.</p> </li> <li> <p><strong>Reading a stream of declared length allocated a buffer of that whole length up front,</strong> up to the maximum buffered jar size. The first buffer is now at most 16MB, and grows as data arrives. A related method doubled its buffer whenever a read returned zero bytes, even when the buffer was not full; no scan was affected, since the streams it is given never return zero.</p> </li> <li> <p><strong>A refused unmap of a buffer view was logged as "Could not unmap ByteBuffer: java.lang.reflect.InvocationTargetException".</strong> Such a view is now refused without a log entry, and any other failure is logged with its real cause.</p> </li> </ul> <h2>Bug fixes: the class graph</h2> <ul> <li> <p><strong><code>ClassInfo#isAnonymousInnerClass()</code> returned true for named local classes.</strong> It now agrees with <code>Class#isAnonymousClass()</code>. <code>getFullyQualifiedDefiningMethodName()</code> returned <code><clinit></code> for a class declared in an instance initializer or an instance field initializer, which javac compiles into the constructors; it now returns null for these, as <code>Class#getEnclosingMethod()</code> does.</p> </li> <li> <p><strong>A local record, enum or interface was reported as not static.</strong></p> </li> </ul> <!-- raw HTML omitted --> </blockquote> <p>... (truncated)</p> </details> <details> <summary>Commits</summary> <ul> <li><a href="https://github.com/classgraph/classgraph/commit/8f16afe2a8483bd8e5f020da31e9b870fb267f4c"><code>8f16afe</code></a> [maven-release-plugin] prepare release classgraph-4.8.196</li> <li><a href="https://github.com/classgraph/classgraph/commit/f0f3d2d43e8d28b9745a3750f844f18d8fd42a51"><code>f0f3d2d</code></a> Declare the element methods in the public list classes, so mockk can mock the...</li> <li><a href="https://github.com/classgraph/classgraph/commit/a4d872db94e0da69f2a460e99bbd20abfe26159e"><code>a4d872d</code></a> [maven-release-plugin] prepare for next development iteration</li> <li><a href="https://github.com/classgraph/classgraph/commit/495b19635b65a39108df3106fc7797dd13e3ed29"><code>495b196</code></a> [maven-release-plugin] prepare release classgraph-4.8.196</li> <li><a href="https://github.com/classgraph/classgraph/commit/4d08ea262561c964c0470189b31a291428f41deb"><code>4d08ea2</code></a> Keep a '$' after a '.' in a class reference as part of the nested class name</li> <li><a href="https://github.com/classgraph/classgraph/commit/67c7d33fcf0655f3abd926dc6da14e7d43f43efb"><code>67c7d33</code></a> Follow an http to https redirect when downloading a jarfile</li> <li><a href="https://github.com/classgraph/classgraph/commit/b8d2225c0fa226c44b35ddb76b716d126f8a2a82"><code>b8d2225</code></a> Check in the LocalRecordTest classfile fixtures, which .gitignore excluded</li> <li><a href="https://github.com/classgraph/classgraph/commit/1eb2fb25040501bed37c492a19fea399ba2afdcb"><code>1eb2fb2</code></a> Make AnnotationParameterValue.equals and hashCode agree with compareTo for un...</li> <li><a href="https://github.com/classgraph/classgraph/commit/707fea6b3a9124485711fbed622f91c6375f45b7"><code>707fea6</code></a> Resolve type variables of an enclosing class, and tell a method's type variab...</li> <li><a href="https://github.com/classgraph/classgraph/commit/534d034cd3004750979a4592941856949d6f4ad1"><code>534d034</code></a> Report local records as static, and fix type annotations on local class const...</li> <li>Additional commits viewable in <a href="https://github.com/classgraph/classgraph/compare/classgraph-4.8.195...classgraph-4.8.196">compare view</a></li> </ul> </details> <br /> [](https://docs.github.com/en/github/managing-security-vulnerabilities/about-dependabot-security-updates#about-compatibility-scores) Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting `@dependabot rebase`. [//]: # (dependabot-automerge-start) [//]: # (dependabot-automerge-end) --- <details> <summary>Dependabot commands and options</summary> <br /> You can trigger Dependabot actions by commenting on this PR: - `@dependabot rebase` will rebase this PR - `@dependabot recreate` will recreate this PR, overwriting any edits that have been made to it - `@dependabot show <dependency name> ignore conditions` will show all of the ignore conditions of the specified dependency - `@dependabot ignore this major version` will close this PR and stop Dependabot creating any more for this major version (unless you reopen the PR or upgrade to it yourself) - `@dependabot ignore this minor version` will close this PR and stop Dependabot creating any more for this minor version (unless you reopen the PR or upgrade to it yourself) - `@dependabot ignore this dependency` will close this PR and stop Dependabot creating any more for this dependency (unless you reopen the PR or upgrade to it yourself) </details> -- This is an automated message from the Apache Git Service. To respond to the message, please log on to GitHub and use the URL above to go to the specific comment. To unsubscribe, e-mail: [email protected] For queries about this service, please contact Infrastructure at: [email protected]
