Skip to content

deps: bump the maven-minor-patch group across 1 directory with 8 updates - #20

Open
dependabot[bot] wants to merge 1 commit into
mainfrom
dependabot/maven/maven-minor-patch-6bdf60fc1e
Open

deps: bump the maven-minor-patch group across 1 directory with 8 updates#20
dependabot[bot] wants to merge 1 commit into
mainfrom
dependabot/maven/maven-minor-patch-6bdf60fc1e

Conversation

@dependabot

@dependabot dependabot Bot commented on behalf of github Aug 24, 2026

Copy link
Copy Markdown

Bumps the maven-minor-patch group with 8 updates in the / directory:

Package From To
io.modelcontextprotocol.sdk:mcp-bom 2.0.0 2.0.1
org.apache.maven.plugins:maven-help-plugin 3.5.1 3.5.2
com.diffplug.spotless:spotless-maven-plugin 3.7.0 3.10.0
org.eclipse.jetty.ee10:jetty-ee10-servlet 12.1.10 12.1.12
org.springframework.security:spring-security-oauth2-resource-server 7.1.0 7.1.1
org.springframework.security:spring-security-config 7.1.0 7.1.1
org.springframework:spring-webmvc 7.0.8 7.0.9
org.springframework.ai:mcp-spring-webmvc 2.0.0 2.0.1

Updates io.modelcontextprotocol.sdk:mcp-bom from 2.0.0 to 2.0.1

Release notes

Sourced from io.modelcontextprotocol.sdk:mcp-bom's releases.

v2.0.1

What's Changed

Depedency updates

New Contributors

Full Changelog: modelcontextprotocol/java-sdk@v2.0.0...v2.0.1

Changelog

Sourced from io.modelcontextprotocol.sdk:mcp-bom's changelog.

2.0.1 — 2026-08-19

  • Bound STDIO and HTTP client/server reads to a configurable maximum size

Full notes: v2.0.1 release

Commits

Updates org.apache.maven.plugins:maven-help-plugin from 3.5.1 to 3.5.2

Release notes

Sourced from org.apache.maven.plugins:maven-help-plugin's releases.

3.5.2

🚀 New features and improvements

🐛 Bug Fixes

📝 Documentation updates

👻 Maintenance

🔧 Build

📦 Dependency updates

Commits
  • bdefec3 [maven-release-plugin] prepare release maven-help-plugin-3.5.2
  • b45833f Update site descriptor to 2.0.0 (#377)
  • 943dd09 [maven-release-plugin] prepare for next development iteration
  • 8a495be [maven-release-plugin] prepare release maven-help-plugin-3.5.2
  • 3ec573e Configure project for ATR (#376)
  • edff852 Add more goals to help plugin (self documenting any Maven version) (#374)
  • 2976b29 Fix issue 367 (#372)
  • 394ea1b Bump org.apache.maven.plugins:maven-plugins from 48 to 49 (#375)
  • 2c155b2 revert broken IT updates from #344
  • 1e716e1 Use version properties in IT (#368)
  • Additional commits viewable in compare view

Updates com.diffplug.spotless:spotless-maven-plugin from 3.7.0 to 3.10.0

Release notes

Sourced from com.diffplug.spotless:spotless-maven-plugin's releases.

Maven Plugin v3.10.0

Added

  • New <shortenFullyQualifiedTypes> step for Java, which replaces fully-qualified type names with their simple names and adds the imports they need. Best combined with <importOrder> and <removeUnusedImports>. (#2945)
  • Add embedded lockfiles to Eclipse JDT for every supported version (4.9 through 4.40), so eclipse() resolves from Maven Central instead of querying a P2 update site. Versions without an embedded lockfile still fall back to P2 provisioning. (#1996)
  • Add support to apply alternate license header within same format (#872)
  • Add support to skip license header application based on source file content pattern (#650).

Fixed

  • removeUnusedImports no longer fails on Java import module declarations. (#2890)
  • Concurrent P2 provisioning no longer races Solstice's on-disk cache (affects Eclipse-based formatters under parallel builds). (#3004)

Changes

  • Default google-java-format remains 1.28.0 on JVM 17; bumps to 1.30.0 on JVM 21+; require at least 1.30.0 on JVM 25+ for import module support.
  • Bump default eclipse version to latest 4.39 -> 4.40. (#1996)
  • Document Maven skip properties spotless.skip, spotless.check.skip, and spotless.apply.skip. Goal-specific skips now live on their own mojos so they no longer leak across goals. (#3009)
  • Bump default adocfmt version 0.2.0 -> 0.3.1, which adds table formatting support (<formatTables>, <tableLayout>, <tableMaxLineWidth>, <tableBlankLines>).

Maven Plugin v3.9.0

Added

Changes

  • Replace RDF formatter library de.atextor:turtle-formatter (discontinued) with cool.rdf:cool-rdf-formatter (its new coordinates); the RDF/turtle formatter now requires Java 25+. (#2995)
  • Bump default greclipse version to latest 4.39 -> 4.40. (#2989)
  • Bump default tabletest-formatter version 1.1.1 -> 1.1.2.

Maven Plugin v3.8.0

Added

  • Add support for custom string format for license header copyright year via yearStringFormat(). (#2965)

Fixed

  • <expandWildcardImports> no longer triggers a full transitive dependency resolution on every build. Dependency resolution is now deferred until the step actually runs, so projects that do not use <expandWildcardImports> (or that use version ranges) are no longer penalized. (#2983)
Commits
  • 426b21d Published maven/3.10.0
  • 2fd42ea Published gradle/8.10.0
  • d71ed1a Published lib/4.10.0
  • 8b57c01 Add shortenFullyQualifiedTypes step (fixes #2945) (#3005 closes #2945)
  • 6b42c5e fix: make the FQN-collecting visitor a named static class
  • 4430823 Better organization on the changelogs.
  • 45bea6d Better place to put the shortenFullyQualifiedTypes docs
  • 0c49e65 chore: spotlessApply
  • 1c5bc0a docs: list the Java import steps in the plugin README tables of contents
  • cd57b58 docs: document shortenFullyQualifiedTypes in the plugin READMEs
  • Additional commits viewable in compare view

Updates org.eclipse.jetty.ee10:jetty-ee10-servlet from 12.1.10 to 12.1.12

Updates org.springframework.security:spring-security-oauth2-resource-server from 7.1.0 to 7.1.1

Release notes

Sourced from org.springframework.security:spring-security-oauth2-resource-server's releases.

7.1.1

⭐ New Features

  • Fix Broken DefaultLoginPageGeneratingFilter Javadoc Link #19252
  • Remove BeanResolver Null Checks #19209
  • Remove Unnecessary AuthorizationDecision Cast #19283
  • Update One-Time Token Docs for Renamed APIs #19274

🪲 Bug Fixes

  • Correct validation logic in CasAuthenticationToken #19372
  • Differentiate Forwarded and X-Forwarded headers in proxy docs #19477
  • Find mixed-case names in InMemoryUserDetailsManager#changePassword #19539
  • Fix OAuth2PushedAuthorizationRequestUri parsing #19445
  • Update JavaDoc Links in Reference #19199
  • Validate Parameter in setPostAuthenticationChecks #19277

🔨 Dependency Upgrades

  • Bump @springio/antora-extensions from 1.14.12 to 1.14.13 in /docs #19503
  • Bump actions/checkout from 6.0.3 to 7.0.0 #19351
  • Bump actions/checkout from 7.0.0 to 7.0.1 #19464
  • Bump actions/setup-java from 5.2.0 to 5.3.0 #19352
  • Bump actions/setup-java from 5.3.0 to 5.4.0 #19380
  • Bump actions/setup-java from 5.4.0 to 5.5.0 #19430
  • Bump actions/setup-java from 5.5.0 to 5.6.0 #19453
  • Bump actions/setup-java from 5.6.0 to 5.7.0 #19501
  • Bump antora from 3.2.0-alpha.12 to 3.2.0-rc.2 in /docs #19385
  • Bump ch.qos.logback:logback-classic from 1.5.34 to 1.5.35 #19374
  • Bump ch.qos.logback:logback-classic from 1.5.35 to 1.5.36 #19389
  • Bump ch.qos.logback:logback-classic from 1.5.36 to 1.5.37 #19396
  • Bump ch.qos.logback:logback-classic from 1.5.37 to 1.5.38 #19431
  • Bump ch.qos.logback:logback-classic from 1.5.38 to 1.6.0 #19467
  • Bump ch.qos.logback:logback-classic from 1.6.0 to 1.6.1 #19476
  • Bump ch.qos.logback:logback-classic from 1.6.1 to 1.6.2 #19556
  • Bump ch.qos.logback:logback-classic from 1.6.2 to 1.6.3 #19564
  • Bump com.fasterxml.jackson:jackson-bom from 2.22.0 to 2.22.1 #19419
  • Bump com.fasterxml.jackson:jackson-bom from 2.22.1 to 2.22.2 #19566
  • Bump com.nimbusds:oauth2-oidc-sdk from 11.37.2 to 11.38.1 #19439
  • Bump com.nimbusds:oauth2-oidc-sdk from 11.38.1 to 11.38.2 #19525
  • Bump com.unboundid:unboundid-ldapsdk from 7.0.4 to 7.0.5 #19322
  • Bump com.webauthn4j:webauthn4j-core from 0.31.6.RELEASE to 0.31.7.RELEASE #19313
  • Bump com.webauthn4j:webauthn4j-core from 0.31.7.RELEASE to 0.31.8.RELEASE #19409
  • Bump com.webauthn4j:webauthn4j-core from 0.31.8.RELEASE to 0.31.9.RELEASE #19496
  • Bump gradle-wrapper from 9.5.1 to 9.6.0 #19360
  • Bump gradle-wrapper from 9.6.0 to 9.6.1 #19393
  • Bump gradle-wrapper from 9.6.1 to 9.7.0 #19516
  • Bump io.spring.nullability:io.spring.nullability.gradle.plugin from 0.0.13 to 0.0.14 #19378
  • Bump org-bouncycastle from 1.84 to 1.85 #19437
  • Bump org-jetbrains-kotlin from 2.4.0 to 2.4.10 #19447

... (truncated)

Commits
  • a825937 Release 7.1.1
  • 74c91f8 Update to Spring Data 2026.0.1
  • b822214 Update to Spring LDAP 4.1.1
  • 39da00f Update to Micrometer 1.17.1
  • 4be80b7 Update to Reactor 2025.0.7
  • 564a677 Update to Spring Framework 7.0.9
  • 2930198 Configure Build for Commercial Repositories
  • 25f9a91 Configure with Commercial Workflows
  • bf8569f Remove OSS CI configuration
  • dcee218 Use jspecify Nullable in DPoPProofReplayValidator
  • Additional commits viewable in compare view

Updates org.springframework.security:spring-security-config from 7.1.0 to 7.1.1

Release notes

Sourced from org.springframework.security:spring-security-config's releases.

7.1.1

⭐ New Features

  • Fix Broken DefaultLoginPageGeneratingFilter Javadoc Link #19252
  • Remove BeanResolver Null Checks #19209
  • Remove Unnecessary AuthorizationDecision Cast #19283
  • Update One-Time Token Docs for Renamed APIs #19274

🪲 Bug Fixes

  • Correct validation logic in CasAuthenticationToken #19372
  • Differentiate Forwarded and X-Forwarded headers in proxy docs #19477
  • Find mixed-case names in InMemoryUserDetailsManager#changePassword #19539
  • Fix OAuth2PushedAuthorizationRequestUri parsing #19445
  • Update JavaDoc Links in Reference #19199
  • Validate Parameter in setPostAuthenticationChecks #19277

🔨 Dependency Upgrades

  • Bump @springio/antora-extensions from 1.14.12 to 1.14.13 in /docs #19503
  • Bump actions/checkout from 6.0.3 to 7.0.0 #19351
  • Bump actions/checkout from 7.0.0 to 7.0.1 #19464
  • Bump actions/setup-java from 5.2.0 to 5.3.0 #19352
  • Bump actions/setup-java from 5.3.0 to 5.4.0 #19380
  • Bump actions/setup-java from 5.4.0 to 5.5.0 #19430
  • Bump actions/setup-java from 5.5.0 to 5.6.0 #19453
  • Bump actions/setup-java from 5.6.0 to 5.7.0 #19501
  • Bump antora from 3.2.0-alpha.12 to 3.2.0-rc.2 in /docs #19385
  • Bump ch.qos.logback:logback-classic from 1.5.34 to 1.5.35 #19374
  • Bump ch.qos.logback:logback-classic from 1.5.35 to 1.5.36 #19389
  • Bump ch.qos.logback:logback-classic from 1.5.36 to 1.5.37 #19396
  • Bump ch.qos.logback:logback-classic from 1.5.37 to 1.5.38 #19431
  • Bump ch.qos.logback:logback-classic from 1.5.38 to 1.6.0 #19467
  • Bump ch.qos.logback:logback-classic from 1.6.0 to 1.6.1 #19476
  • Bump ch.qos.logback:logback-classic from 1.6.1 to 1.6.2 #19556
  • Bump ch.qos.logback:logback-classic from 1.6.2 to 1.6.3 #19564
  • Bump com.fasterxml.jackson:jackson-bom from 2.22.0 to 2.22.1 #19419
  • Bump com.fasterxml.jackson:jackson-bom from 2.22.1 to 2.22.2 #19566
  • Bump com.nimbusds:oauth2-oidc-sdk from 11.37.2 to 11.38.1 #19439
  • Bump com.nimbusds:oauth2-oidc-sdk from 11.38.1 to 11.38.2 #19525
  • Bump com.unboundid:unboundid-ldapsdk from 7.0.4 to 7.0.5 #19322
  • Bump com.webauthn4j:webauthn4j-core from 0.31.6.RELEASE to 0.31.7.RELEASE #19313
  • Bump com.webauthn4j:webauthn4j-core from 0.31.7.RELEASE to 0.31.8.RELEASE #19409
  • Bump com.webauthn4j:webauthn4j-core from 0.31.8.RELEASE to 0.31.9.RELEASE #19496
  • Bump gradle-wrapper from 9.5.1 to 9.6.0 #19360
  • Bump gradle-wrapper from 9.6.0 to 9.6.1 #19393
  • Bump gradle-wrapper from 9.6.1 to 9.7.0 #19516
  • Bump io.spring.nullability:io.spring.nullability.gradle.plugin from 0.0.13 to 0.0.14 #19378
  • Bump org-bouncycastle from 1.84 to 1.85 #19437
  • Bump org-jetbrains-kotlin from 2.4.0 to 2.4.10 #19447

... (truncated)

Commits
  • a825937 Release 7.1.1
  • 74c91f8 Update to Spring Data 2026.0.1
  • b822214 Update to Spring LDAP 4.1.1
  • 39da00f Update to Micrometer 1.17.1
  • 4be80b7 Update to Reactor 2025.0.7
  • 564a677 Update to Spring Framework 7.0.9
  • 2930198 Configure Build for Commercial Repositories
  • 25f9a91 Configure with Commercial Workflows
  • bf8569f Remove OSS CI configuration
  • dcee218 Use jspecify Nullable in DPoPProofReplayValidator
  • Additional commits viewable in compare view

Updates org.springframework:spring-webmvc from 7.0.8 to 7.0.9

Release notes

Sourced from org.springframework:spring-webmvc's releases.

v7.0.9

⚠️ Attention Required

  • In Spring Framework 7.0.9, ForwardedHeaderFilter (Spring MVC) and ForwardedHeaderTransformer (WebFlux) each provide a boolean constructor argument whether to use the standard "Forwarded" header or the "X-Forwarded" alternative headers. A separate property turns on and off use of "X-Forwarded-Prefix". While the default constructor preserves the existing behavior, we recommend to use the new constructor to explicitly specify which forwarded headers to use to make the processing more deterministic and aligned with what is expected from the proxy. Please, see the updated Security Considerations section for details. In 7.1 with #37072 the default constructor is deprecated and marked for removal. #37090
  • In Spring Framework 7.0.9, SimpleEvaluationContext no longer supports expression compilation by default, regardless of the compiler mode configured via SpelParserConfiguration or the spring.expression.compiler.mode system property or Spring property. Applications that intentionally use SimpleEvaluationContext with trusted expressions and require compilation for performance reasons can opt in by calling withCompilationSupported() on the SimpleEvaluationContext builder. Care should be taken when opting in to compilation, as doing so removes the safety guards applied during interpreted evaluation. #37035

⭐ New Features

  • Ignore an empty port value in URI parsing #37117
  • Avoid retaining class files in annotation metadata #37112
  • Add @Nullable annotations when treating Map.remove() as returning @Nullable #37067
  • Revisit SSE view fragments handling #37061
  • Check list index after auto-grow in AbstractNestablePropertyAccessor #37036
  • Disable SpEL expression compilation by default in SimpleEvaluationContext #37035
  • Limit result size of BigDecimal/BigInteger power operations in SpEL #37034
  • Refactor redirect handling in UrlHandlerFilter #37030
  • Revise stylesheet source handling in XsltView #37029
  • Revise view name handling in UrlFilenameViewController #37027
  • Handle pre-flight requests in functional endpoint setup without DispatcherHandler #37024
  • Improve WebSocket handshake error logging #37023
  • Fix missing nullability in JdbcTemplate.batchUpdate #37012
  • Timeout property in RetryPolicy does not have a default constant #36983
  • Write native configuration files as UTF-8 #36972
  • DefaultServerRequest.ServletParametersMap.entrySet() does not retain HttpServletRequest.getParameterMap() order #36966
  • Perform nextKey within synchronization for SQLite as well #36959
  • Add support for custom ObjectInputFilter on DefaultDeserializer #36958
  • Revise resource bundle caching for common locales #36957
  • Improve nullability for getSession(*) in MockHttpServletRequest #36926
  • Improve fallback logic in ParameterContentNegotiationStrategy and ParameterContentTypeResolver #36925
  • Improve ambiguous match check on preflight request #36903
  • Improve Groovy markup template loading #36902
  • Improve request path handling on a Reactor Netty server #36893
  • Improve JettyWebSocketSession error handling #36891

🐞 Bug Fixes

  • EclipseLinkJpaDialect singleton lock in EclipseLinkConnectionHandle.getConnection() serializes all JDBC connection acquisitions under load #37085
  • MetadataReader fails to read byte[] array from annotation #37083
  • Ensure parsing/tostring symmetry in ContentDisposition #37064
  • Character outside of permitted range in Content Disposition #37062
  • Release Jackson BufferRecycler to its pool in encoders #37059
  • Ensure consistent error escaping #37055
  • Refine template name processing #37054
  • Reset TwoByteMatcher partial match on mismatching byte #37053
  • Refactor async XML parsing limit checks #37031
  • Fix part constraint checks in PartEventHttpMessageReader #37028
  • Fix buffer leak in RSocket SETUP frame handling #37026
  • Ensure correct Jetty core response cookie handling #37025
  • Align domainToAscii with current WhatWG spec #37018
  • Ensure consistent ButtonTag value attribute processing #37017

... (truncated)

Commits
  • 82a6b40 Release Spring Framework 7.0.9
  • a7b1b59 Upgrade to Reactor 2025.0.7
  • 996e3d3 Upgrade to Micrometer 1.16.7
  • 73f5ddd Refactor maxInMemory limit handling for async XML parsing
  • 675f25d Leading slash handling in UrlHandlerFilter
  • 692dbc9 Apply ResourceHandlerUtils checks in XsltView
  • 8647e90 Consistent maxPartSize check in PartEventHttpMessageReader
  • b9379e3 Check viewName for special prefixes in UrlFilenameViewController
  • a784dbe Ensure Payload release on early error in createHeaders
  • 3b492f3 Return sameSite cookie value in Jetty response
  • Additional commits viewable in compare view

Updates org.springframework.ai:mcp-spring-webmvc from 2.0.0 to 2.0.1

Release notes

Sourced from org.springframework.ai:mcp-spring-webmvc's releases.

Spring AI 2.0.1

For upgrading from 2.0.0 to 2.0.1, please refer to the upgrade notes here.

For the detailed reference documentation on 2.0.1, please refer here

⭐ New Features

  • Harden Ollama integration tests against flakiness #6776
  • Retire deprecated Mistral AI chat models #6772
  • Document additional 2.0.1 breaking changes #6771
  • Support audio streaming in OpenAiAudioSpeechModel #6733
  • Add configurable tool call limits #6726
  • Enrich OpenAI transcription options and responses #6697
  • Update Couchbase vector store to use Spring Boot-managed client #6583
  • Remove explicit protobuf-java version properties #6552
  • Add ToolChoice support for Google GenAI chat model #6531
  • Remove fastjson2 dependency from spring-ai-azure-store #6508
  • Refactor Media builder to use typed data overloads #6481
  • Validate TokenTextSplitter builder arguments #6452
  • Support page ranges in PagePdfDocumentReader #6445
  • Revise DeepSeekApi #6428
  • GraalVM for mcp annotations doesn't work in Spring AI 2.0.0 #6427
  • Rename spring-ai-autoconfigure-model-chat-memory-redis #6416
  • Restore PDF media mapping in OpenAiChatModel #6410
  • Google Image generation support #6408
  • Remove unused field maxResults #6344
  • Confusing WARN log while AWS region resolving #5108
  • SpringAI does not follow the AWS SDK's default region resolution rules #823

🐞 Bug Fixes

  • Reserve Redis chat memory timestamps atomically #6784
  • Fix RedisChatMemoryRepository clear() #6783
  • Escape metadata values in Redis chat memory queries #6765
  • Validate resolved resource path #6764
  • Introduce maxSessions and sessionIdleTimeout #6760
  • Fix OpenAiAudioTranscriptionModel leaking the stream on cancellation #6759
  • Merge java-compile compilerArgs instead of overriding #6756
  • Default OpenAI tool-calling strict mode to false #6755
  • Use temporary directory for cache #6754
  • Handle malformed pdf in PdfDocumentReader #6753
  • Make tool resolution fallback configurable #6751
  • Use full length hash #6746
  • Correct ToolContext parameter detection #6744
  • Return a single Generation on ToolCallLimitExceededException #6742
  • Fix ToolCallingAdvisor streaming loop dropping doBeforeStream mutations #6737
  • Add instructions option to OpenAiAudioSpeechModel #6731
  • Apply MCP HTTP client request customizer beans #6716
  • Close OpenAI stream response on cancellation #6656
  • Validate text length to prevent StringIndexOutOfBoundsException for MarkdownCodeBlockCleaner #6645

... (truncated)

Commits
  • c9107fd Release 2.0.1
  • 92a2119 Upgrade to Spring Boot 4.1.1
  • 0e7b5f6 Escape metadata values in Redis chat memory queries
  • 2d2b455 Validate resolved resource path stays within the cache directory
  • 023867c Introduce maxSessions and sessionIdleTimeout
  • 8a1fd8e Handle malformed pdf in PdfDocumentReader
  • 369a926 Use a new temporary directory for cache
  • 096f140 Make tool resolution fallback configurable
  • d89e4a4 Use full length SHA256 hash for contextHash
  • 3fc390f Prepare 2.0.x-internal branch
  • Additional commits viewable in compare view

Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting @dependabot rebase.


Dependabot commands and options

You can trigger Dependabot actions by commenting on this PR:

  • @dependabot rebase will rebase this PR
  • @dependabot recreate will recreate this PR, overwriting any edits that have been made to it
  • @dependabot show <dependency name> ignore conditions will show all of the ignore conditions of the specified dependency
  • @dependabot ignore <dependency name> major version will close this group update PR and stop Dependabot creating any more for the specific dependency's major version (unless you unignore this specific dependency's major version or upgrade to it yourself)
  • @dependabot ignore <dependency name> minor version will close this group update PR and stop Dependabot creating any more for the specific dependency's minor version (unless you unignore this specific dependency's minor version or upgrade to it yourself)
  • @dependabot ignore <dependency name> will close this group update PR and stop Dependabot creating any more for the specific dependency (unless you unignore this specific dependency or upgrade to it yourself)
  • @dependabot unignore <dependency name> will remove all of the ignore conditions of the specified dependency
  • @dependabot unignore <dependency name> <ignore condition> will remove the ignore condition of the specified dependency and ignore conditions

Bumps the maven-minor-patch group with 8 updates in the / directory:

| Package | From | To |
| --- | --- | --- |
| [io.modelcontextprotocol.sdk:mcp-bom](https://github.com/modelcontextprotocol/java-sdk) | `2.0.0` | `2.0.1` |
| [org.apache.maven.plugins:maven-help-plugin](https://github.com/apache/maven-help-plugin) | `3.5.1` | `3.5.2` |
| [com.diffplug.spotless:spotless-maven-plugin](https://github.com/diffplug/spotless) | `3.7.0` | `3.10.0` |
| org.eclipse.jetty.ee10:jetty-ee10-servlet | `12.1.10` | `12.1.12` |
| [org.springframework.security:spring-security-oauth2-resource-server](https://github.com/spring-projects/spring-security) | `7.1.0` | `7.1.1` |
| [org.springframework.security:spring-security-config](https://github.com/spring-projects/spring-security) | `7.1.0` | `7.1.1` |
| [org.springframework:spring-webmvc](https://github.com/spring-projects/spring-framework) | `7.0.8` | `7.0.9` |
| [org.springframework.ai:mcp-spring-webmvc](https://github.com/spring-projects/spring-ai) | `2.0.0` | `2.0.1` |



Updates `io.modelcontextprotocol.sdk:mcp-bom` from 2.0.0 to 2.0.1
- [Release notes](https://github.com/modelcontextprotocol/java-sdk/releases)
- [Changelog](https://github.com/modelcontextprotocol/java-sdk/blob/main/CHANGELOG.md)
- [Commits](modelcontextprotocol/java-sdk@v2.0.0...v2.0.1)

Updates `org.apache.maven.plugins:maven-help-plugin` from 3.5.1 to 3.5.2
- [Release notes](https://github.com/apache/maven-help-plugin/releases)
- [Commits](apache/maven-help-plugin@maven-help-plugin-3.5.1...maven-help-plugin-3.5.2)

Updates `com.diffplug.spotless:spotless-maven-plugin` from 3.7.0 to 3.10.0
- [Release notes](https://github.com/diffplug/spotless/releases)
- [Changelog](https://github.com/diffplug/spotless/blob/main/CHANGES.md)
- [Commits](diffplug/spotless@maven/3.7.0...maven/3.10.0)

Updates `org.eclipse.jetty.ee10:jetty-ee10-servlet` from 12.1.10 to 12.1.12

Updates `org.springframework.security:spring-security-oauth2-resource-server` from 7.1.0 to 7.1.1
- [Release notes](https://github.com/spring-projects/spring-security/releases)
- [Changelog](https://github.com/spring-projects/spring-security/blob/main/RELEASE.adoc)
- [Commits](spring-projects/spring-security@7.1.0...7.1.1)

Updates `org.springframework.security:spring-security-config` from 7.1.0 to 7.1.1
- [Release notes](https://github.com/spring-projects/spring-security/releases)
- [Changelog](https://github.com/spring-projects/spring-security/blob/main/RELEASE.adoc)
- [Commits](spring-projects/spring-security@7.1.0...7.1.1)

Updates `org.springframework:spring-webmvc` from 7.0.8 to 7.0.9
- [Release notes](https://github.com/spring-projects/spring-framework/releases)
- [Commits](spring-projects/spring-framework@v7.0.8...v7.0.9)

Updates `org.springframework.ai:mcp-spring-webmvc` from 2.0.0 to 2.0.1
- [Release notes](https://github.com/spring-projects/spring-ai/releases)
- [Changelog](https://github.com/spring-projects/spring-ai/blob/main/release-train-settings.xml)
- [Commits](spring-projects/spring-ai@v2.0.0...v2.0.1)

---
updated-dependencies:
- dependency-name: io.modelcontextprotocol.sdk:mcp-bom
  dependency-version: 2.0.1
  dependency-type: direct:production
  update-type: version-update:semver-patch
  dependency-group: maven-minor-patch
- dependency-name: org.apache.maven.plugins:maven-help-plugin
  dependency-version: 3.5.2
  dependency-type: direct:development
  update-type: version-update:semver-patch
  dependency-group: maven-minor-patch
- dependency-name: com.diffplug.spotless:spotless-maven-plugin
  dependency-version: 3.10.0
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: maven-minor-patch
- dependency-name: org.eclipse.jetty.ee10:jetty-ee10-servlet
  dependency-version: 12.1.12
  dependency-type: direct:production
  update-type: version-update:semver-patch
  dependency-group: maven-minor-patch
- dependency-name: org.springframework.security:spring-security-oauth2-resource-server
  dependency-version: 7.1.1
  dependency-type: direct:production
  update-type: version-update:semver-patch
  dependency-group: maven-minor-patch
- dependency-name: org.springframework.security:spring-security-config
  dependency-version: 7.1.1
  dependency-type: direct:production
  update-type: version-update:semver-patch
  dependency-group: maven-minor-patch
- dependency-name: org.springframework:spring-webmvc
  dependency-version: 7.0.9
  dependency-type: direct:production
  update-type: version-update:semver-patch
  dependency-group: maven-minor-patch
- dependency-name: org.springframework.ai:mcp-spring-webmvc
  dependency-version: 2.0.1
  dependency-type: direct:production
  update-type: version-update:semver-patch
  dependency-group: maven-minor-patch
...

Signed-off-by: dependabot[bot] <support@github.com>
@dependabot dependabot Bot added dependencies Pull requests that update a dependency java Related to the Java SDK or Maven labels Aug 24, 2026
@dependabot
dependabot Bot requested a review from a team as a code owner August 24, 2026 13:18
@dependabot dependabot Bot added dependencies Pull requests that update a dependency java Related to the Java SDK or Maven labels Aug 24, 2026
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

dependencies Pull requests that update a dependency java Related to the Java SDK or Maven

Projects

None yet

Development

Successfully merging this pull request may close these issues.

0 participants