dependabot[bot] opened a new pull request, #27476:
URL: https://github.com/apache/camel/pull/27476

   Bumps [dev.toonformat:jtoon](https://github.com/toon-format/toon-java) from 
2.0.4 to 2.0.5.
   <details>
   <summary>Release notes</summary>
   <p><em>Sourced from <a 
href="https://github.com/toon-format/toon-java/releases";>dev.toonformat:jtoon's 
releases</a>.</em></p>
   <blockquote>
   <h2>v2.0.5</h2>
   <p>Spec 4.1.2 alignment with security/version handling, documentation and 
changelog updates.</p>
   <h2>What's Changed</h2>
   <ul>
   <li>Jackson update by <a 
href="https://github.com/jenspapenhagen";><code>@​jenspapenhagen</code></a> in 
<a 
href="https://redirect.github.com/toon-format/toon-java/pull/196";>toon-format/toon-java#196</a></li>
   <li>docs: record out-of-scope decisions by <a 
href="https://github.com/johannschopplich";><code>@​johannschopplich</code></a> 
in <a 
href="https://redirect.github.com/toon-format/toon-java/pull/198";>toon-format/toon-java#198</a></li>
   <li>docs: tighten out-of-scope records by <a 
href="https://github.com/johannschopplich";><code>@​johannschopplich</code></a> 
in <a 
href="https://redirect.github.com/toon-format/toon-java/pull/199";>toon-format/toon-java#199</a></li>
   <li>chore(deps): bump actions/setup-java from 6.0.0 to 6.0.1 by <a 
href="https://github.com/dependabot";><code>@​dependabot</code></a>[bot] in <a 
href="https://redirect.github.com/toon-format/toon-java/pull/197";>toon-format/toon-java#197</a></li>
   <li>fix(decoder): reject the removed <code>[#N]</code> length marker by <a 
href="https://github.com/johannschopplich";><code>@​johannschopplich</code></a> 
in <a 
href="https://redirect.github.com/toon-format/toon-java/pull/200";>toon-format/toon-java#200</a></li>
   <li>fix(encoder): reject strings with unpaired surrogates by <a 
href="https://github.com/johannschopplich";><code>@​johannschopplich</code></a> 
in <a 
href="https://redirect.github.com/toon-format/toon-java/pull/202";>toon-format/toon-java#202</a></li>
   <li>Spec 4.1.2 alignment: wrapper hash, release workflow guard, docs 
examples, changelog/FORMAT/README by <a 
href="https://github.com/jenspapenhagen";><code>@​jenspapenhagen</code></a> in 
<a 
href="https://redirect.github.com/toon-format/toon-java/pull/206";>toon-format/toon-java#206</a></li>
   </ul>
   <p><strong>Full Changelog</strong>: <a 
href="https://github.com/toon-format/toon-java/compare/v2.0.4...v2.0.5";>https://github.com/toon-format/toon-java/compare/v2.0.4...v2.0.5</a></p>
   </blockquote>
   </details>
   <details>
   <summary>Changelog</summary>
   <p><em>Sourced from <a 
href="https://github.com/toon-format/toon-java/blob/main/CHANGELOG.md";>dev.toonformat:jtoon's
 changelog</a>.</em></p>
   <blockquote>
   <h2>[2.0.5] - 2026-10-03</h2>
   <h3>Fixed</h3>
   <ul>
   <li><strong>Token trimming is now exactly U+0020</strong>, as §12 requires. 
<code>String.trim()</code>, <code>String.isBlank()</code> and 
<code>String.stripTrailing()</code> also removed tabs and control characters, 
so <code>key: value&lt;tab&gt;</code> decoded as <code>value</code>, and 
<code>key: &quot;a&quot;&lt;tab&gt;</code> was accepted even though §7.4 
requires the quoted token to end with its closing quote. A trailing tab at the 
end of a line is now line content. A single U+FEFF at the very start of a 
document is still stripped as a byte-order mark (§12).</li>
   <li><strong>Any character after the closing quote of a quoted token is now 
rejected in key position</strong> as well as in value position (§7.4).</li>
   <li><strong>Root-form discovery starts at the first non-blank line</strong> 
instead of assuming line 0, so a document with leading blank lines is no longer 
misparsed (§5).</li>
   <li><strong>An unquoted key token may contain spaces.</strong> <code>foo 
bar[2]: 1,2</code> now decodes with the literal key <code>foo bar</code>, which 
§7.4 requires of decoders. Whitespace between a key and its bracket segment 
(<code>foo [2]:</code>) remains a header syntax error (§6, §14.2).</li>
   <li><strong>A root string value starting with U+FEFF is now quoted</strong>, 
as §7.2 requires; unquoted, a conforming decoder would strip it as a byte-order 
mark and silently lose the character (§12). This is the one normative behaviour 
change in spec 4.1.2.</li>
   </ul>
   <h3>Changed</h3>
   <ul>
   <li>Conformance raised from spec 4.1.1 to <strong>4.1.2</strong>, which is a 
single normative change: a root primitive starting with U+FEFF must be quoted 
(§7.2). On top of that, decoder strictness was tightened in five places where 
the implementation accepted input the spec rejects — token trimming, 
quoted-token boundaries, root-form discovery, header key tokens and the 
<code>[N]</code> length marker. The full conformance suite from 4.1 (canonical 
number formatting, BOM stripping, comment pre-pass §5.1, strict header 
validation §5/§6/§7.3/§7.4, nested field groups in tabular arrays §9.3, keyed 
tabular form §9.5/§10, non-strict tab leniency §12) carries over unchanged and 
remains green. The 24 conformance fixture files are byte-identical to the spec 
repository at tag <code>v4.1.2</code>.</li>
   <li>Upstream [PR <a 
href="https://redirect.github.com/toon-format/toon-java/issues/201";>#201</a>](<a
 
href="https://redirect.github.com/toon-format/toon-java/pull/201";>toon-format/toon-java#201</a>)
 integrated (squash merge). Conflicts in <code>KeyDecoder</code>, 
<code>ListItemDecoder</code> and <code>ValueDecoder</code> were resolved 
additively, keeping both the <code>validateQuotedTokenBoundary</code> check 
from <a 
href="https://redirect.github.com/toon-format/toon-java/issues/201";>#201</a> 
and the <code>validateKeyHasNoUnquotedBrackets</code> check from <a 
href="https://redirect.github.com/toon-format/toon-java/issues/200";>#200</a>. 
<code>DecodeHelper.trimSpaces()</code> remains the canonical token trimmer.</li>
   <li>The targeted specification version is now declared as <code>toon-spec: 
4.1.2</code> in the README, as §13 recommends.</li>
   </ul>
   <h3>Documentation</h3>
   <ul>
   <li><code>README.md</code>: spec badge updated to v4.1.2; corrected a stale 
quick-start example that showed the non-conforming legacy empty-array form 
<code>preferences[0]:</code> instead of <code>preferences: []</code> 
(§9.1).</li>
   <li><code>docs/FORMAT.md</code> audited against the spec and corrected. The 
most serious defect was a flat contradiction: the document stated 
<em>&quot;TOON does not support comments&quot;</em>, while §5.1 defines 
full-line comments and the decoder has always implemented the comment pre-pass. 
Also corrected: empty arrays (§9.1, was the stale <code>items[0]:</code> form), 
number notation (§2, was stated as an absolute MUST where the spec only 
requires canonical decimal inside the canonical range and permits exponent 
notation outside it), nested-uniform tabular columns (§9.3), decoder key 
permissiveness (§7.4), and the quoting triggers for a leading <code>-</code> or 
<code>#</code> and for a root primitive starting with U+FEFF (§7.2).</li>
   <li><code>docs/FORMAT.md</code> gained the normative sections that were 
missing entirely: Keyed Tabular Arrays (§9.5), Header Syntax (§6), Quoted Token 
Boundaries (§7.4), line terminators and the BOM (§12), the two delimiter scopes 
(§11.1) and the full strict-mode error set (§14).</li>
   <li><code>util/package-info.java</code>: the documented unquoted-key pattern 
was <code>^[A-Z_][\w.]*$</code>, which is wrong — it excluded lowercase keys 
that the encoder in fact emits unquoted. Corrected to the spec's 
<code>^[A-Za-z_][A-Za-z0-9_.]*$</code> (§7.3), with a note that §7.3 constrains 
encoders only while decoders accept any token. The quoting trigger was 
documented as <code>- </code> (dash-space) rather than a hyphen at position 0, 
and the <code>#</code> trigger, the root U+FEFF trigger and 
<code>Constants.BYTE_ORDER_MARK</code> were missing.</li>
   <li><code>docs/javadoc/</code> regenerated. 20 pages had never been 
generated at all — the checked-in output predated the decoder, encoder and 
validator packages, so <code>Headers</code>, <code>KeyFolding</code>, every 
<code>decoder/*</code> class and the whole <code>validator</code> package were 
absent. 88 → 109 pages.</li>
   </ul>
   <h3>Build and Tooling</h3>
   <ul>
   <li>Gradle wrapper <strong>9.7.1 → 9.8.0</strong>.</li>
   <li>NullAway <strong>0.14.1 → 0.14.2</strong>.</li>
   <li>SpotBugs Gradle plugin <strong>6.5.11 → 6.5.12</strong>.</li>
   <li><code>gradle/verification-metadata.xml</code> <strong>regenerated from 
scratch</strong> instead of merged: <strong>3786 → 2821 lines, 522 → 398 
components</strong>. The removed entries were artifacts of dependencies that 
have left the graph. Regenerated under Gradle 9.8.0 and spot-checked against 
Maven Central's published SHA1 checksums.</li>
   <li>Removed <code>gradle/verification-metadata.dryrun.xml</code>, a leftover 
from an earlier dry run that Gradle never reads and that nothing in the 
repository referenced.</li>
   <li>The <code>update-verification</code> workflow no longer lets stale 
entries accumulate: <code>--write-verification-metadata</code> <em>merges</em> 
into an existing file rather than replacing it, so the workflow now deletes the 
file first and then regenerates. A subsequent verification-enabled build was 
added as a self-check, since the write mode tolerates verification failures by 
design.</li>
   <li><code>README.md</code> and <code>CONTRIBUTING.md</code> document the 
delete-then-regenerate procedure, so the merge behaviour is not reintroduced 
locally.</li>
   <li>Checkstyle is clean again: <code>PrimitiveEncoder</code> overloads 
reordered, and the U+FEFF literal in <code>Constants</code> expressed without 
an escaped unicode character.</li>
   </ul>
   <h3>Tests</h3>
   <ul>
   <li>New <code>HeadersTest</code> coverage for §7.4 key tokens: keys 
containing a hyphen, a leading digit, an internal space, a tab, a non-breaking 
space and a quoted key; rejection of a space before the bracket segment and 
before the colon, and of content between the bracket segment and the colon.</li>
   <li>New <code>PrimitiveEncoderTest</code> coverage for the §7.2 root 
byte-order-mark rule: a root string starting with U+FEFF is quoted, a bare 
U+FEFF is quoted, and U+FEFF stays unquoted both in non-root position and in 
the interior of a root string.</li>
   <li>Full suite: <strong>1870 tests, 0 failures</strong>, with dependency 
verification enabled.</li>
   </ul>
   </blockquote>
   </details>
   <details>
   <summary>Commits</summary>
   <ul>
   <li><a 
href="https://github.com/toon-format/toon-java/commit/9e0ab99889337927b89becbe38e1bc9eaa6dda86";><code>9e0ab99</code></a>
 fix(workflow): make jacoco badge step non-blocking (<a 
href="https://redirect.github.com/toon-format/toon-java/issues/214";>#214</a>)</li>
   <li><a 
href="https://github.com/toon-format/toon-java/commit/c471299fd9fc9d86d271b4b95b9860f7e559eb94";><code>c471299</code></a>
 fix(workflow): add --clobber to gh release upload (<a 
href="https://redirect.github.com/toon-format/toon-java/issues/213";>#213</a>)</li>
   <li><a 
href="https://github.com/toon-format/toon-java/commit/587d2d72a4276de8f2d6269fca05d643acd03cc9";><code>587d2d7</code></a>
 fix(workflow): update jacoco-badge-generator inputs for v2.12.1 (<a 
href="https://redirect.github.com/toon-format/toon-java/issues/212";>#212</a>)</li>
   <li><a 
href="https://github.com/toon-format/toon-java/commit/fb3ff6b8de604a2d893d318fc108c03e025edb37";><code>fb3ff6b</code></a>
 fix(workflow): use gh release upload for assets (<a 
href="https://redirect.github.com/toon-format/toon-java/issues/211";>#211</a>)</li>
   <li><a 
href="https://github.com/toon-format/toon-java/commit/17321133f0cc7771964460455d57edfc0992669d";><code>1732113</code></a>
 fix(workflow): add GH_TOKEN env for release creation (<a 
href="https://redirect.github.com/toon-format/toon-java/issues/210";>#210</a>)</li>
   <li><a 
href="https://github.com/toon-format/toon-java/commit/cc836be15cab055d153daa81f8d256f702d6119d";><code>cc836be</code></a>
 docs: update version to 2.0.5 in README</li>
   <li><a 
href="https://github.com/toon-format/toon-java/commit/c9fe6664fa4a106f1494ac3d966ebee45806494f";><code>c9fe666</code></a>
 fix(workflow): fix shell syntax in maven central credentials check (<a 
href="https://redirect.github.com/toon-format/toon-java/issues/209";>#209</a>)</li>
   <li><a 
href="https://github.com/toon-format/toon-java/commit/cf1991576269f310a67a6b2cc2bea218f31d099c";><code>cf19915</code></a>
 auto: update dependency verification metadata [skip ci]</li>
   <li><a 
href="https://github.com/toon-format/toon-java/commit/e9a5e6c9627ba91e8e9e7163670866390705b7d1";><code>e9a5e6c</code></a>
 fix(workflow): regenerate verification metadata before specs validation (<a 
href="https://redirect.github.com/toon-format/toon-java/issues/208";>#208</a>)</li>
   <li><a 
href="https://github.com/toon-format/toon-java/commit/6e795a59e36a0137c9c1356ac6309f5b2082a16f";><code>6e795a5</code></a>
 fix: regenerate dependency verification metadata for Gradle 9.8.0 transitive 
...</li>
   <li>Additional commits viewable in <a 
href="https://github.com/toon-format/toon-java/compare/v2.0.4...v2.0.5";>compare 
view</a></li>
   </ul>
   </details>
   <br />
   
   
   [![Dependabot compatibility 
score](https://dependabot-badges.githubapp.com/badges/compatibility_score?dependency-name=dev.toonformat:jtoon&package-manager=maven&previous-version=2.0.4&new-version=2.0.5)](https://docs.github.com/en/github/managing-security-vulnerabilities/about-dependabot-security-updates#about-compatibility-scores)
   
   Dependabot will resolve any conflicts with this PR as long as you don't 
alter it yourself. You can also trigger a rebase manually by commenting 
`@dependabot rebase`.
   
   [//]: # (dependabot-automerge-start)
   [//]: # (dependabot-automerge-end)
   
   ---
   
   <details>
   <summary>Dependabot commands and options</summary>
   <br />
   
   You can trigger Dependabot actions by commenting on this PR:
   - `@dependabot rebase` will rebase this PR
   - `@dependabot recreate` will recreate this PR, overwriting any edits that 
have been made to it
   - `@dependabot show <dependency name> ignore conditions` will show all of 
the ignore conditions of the specified dependency
   - `@dependabot ignore this major version` will close this PR and stop 
Dependabot creating any more for this major version (unless you reopen the PR 
or upgrade to it yourself)
   - `@dependabot ignore this minor version` will close this PR and stop 
Dependabot creating any more for this minor version (unless you reopen the PR 
or upgrade to it yourself)
   - `@dependabot ignore this dependency` will close this PR and stop 
Dependabot creating any more for this dependency (unless you reopen the PR or 
upgrade to it yourself)
   
   
   </details>


-- 
This is an automated message from the Apache Git Service.
To respond to the message, please log on to GitHub and use the
URL above to go to the specific comment.

To unsubscribe, e-mail: [email protected]

For queries about this service, please contact Infrastructure at:
[email protected]

Reply via email to