Skip to content

Conversation

@renovate
Copy link
Contributor

@renovate renovate bot commented Oct 20, 2025

This PR contains the following updates:

Package Type Update Change Age Confidence
github/codeql-action action patch v4.30.8 -> v4.30.9 age confidence
org.jetbrains.kotlinx.kover plugin patch 0.9.2 -> 0.9.3 age confidence
io.quarkus plugin patch 3.28.3 -> 3.28.4 age confidence
io.quarkus:quarkus-junit5 dependencies patch 3.28.3 -> 3.28.4 age confidence
io.quarkus:quarkus-arc dependencies patch 3.28.3 -> 3.28.4 age confidence
io.quarkus:quarkus-bom dependencies patch 3.28.3 -> 3.28.4 age confidence

Release Notes

github/codeql-action (github/codeql-action)

v4.30.9

Compare Source

CodeQL Action Changelog

See the releases page for the relevant changes to the CodeQL CLI and language packs.

4.30.9 - 17 Oct 2025
  • Update default CodeQL bundle version to 2.23.3. #​3205
  • Experimental: A new setup-codeql action has been added which is similar to init, except it only installs the CodeQL CLI and does not initialize a database. Do not use this in production as it is part of an internal experiment and subject to change at any time. #​3204

See the full CHANGELOG.md for more information.

quarkusio/quarkus (io.quarkus:quarkus-junit5)

v3.28.4

Compare Source

Complete changelog
  • #​49225 - OIDC redirect fails to properly append OAuth parameters when original URL contains query parameters
  • #​50321 - @RequestParam required true
  • #​50400 - Modify @RequestParam presence handling
  • #​50427 - DEV UI workspace shows a log file on Windows rather than Java file and hierarchy visualisation is broken
  • #​50476 - Rename leftovers of GlobalDevServicesConfig
  • #​50490 - Fix DEV UI workspace directory worktree and item selection on Windows
  • #​50491 - Correctly restore query params when OIDC does not drop redirect params
  • #​50503 - Add a clarification about OAuth2 protected resource metadata route address
  • #​50515 - Move Hibernate ORM/Reactive configuration reference to the bottom of the guides
  • #​50517 - Assistant: Remove unused exception method
  • #​50520 - Minor update to rest-client.adoc
  • #​50528 - Project creation with extension not from platform fails with 3.28.3
  • #​50531 - Update logging configuration property from .enable to .enabled in application properties
  • #​50541 - Bump the hibernate group with 8 updates
  • #​50554 - Ignore quarkus-core in non-platform extension catalogs
  • #​50556 - Quarkus augmentation weakens file permissions
  • #​50557 - Avoid using COPY_ATTRIBUTES when copying the jars of fast jar
  • #​50560 - UnsupportedOperationException with HTTP Response Code 204
  • #​50569 - Don't fail in Quarkus REST Servlet when trying to remove an HTTP header

Configuration

📅 Schedule: Branch creation - Between 12:00 AM and 03:59 AM, only on Monday ( * 0-3 * * 1 ) (UTC), Automerge - At any time (no schedule defined).

🚦 Automerge: Disabled by config. Please merge this manually once you are satisfied.

Rebasing: Whenever PR is behind base branch, or you tick the rebase/retry checkbox.

👻 Immortal: This PR will be recreated if closed unmerged. Get config help if that's undesired.


  • If you want to rebase/retry this PR, check this box

This PR was generated by Mend Renovate. View the repository job log.

# Commenting out will disable upload of results to your repo's Code Scanning dashboard
- name: "Upload to code-scanning"
uses: github/codeql-action/[email protected].8
uses: github/codeql-action/[email protected].9

Check warning

Code scanning / Scorecard

Pinned-Dependencies Medium

score is 0: GitHub-owned GitHubAction not pinned by hash
Remediation tip: update your workflow using https://app.stepsecurity.io
Click Remediation section below for further remediation help
@osoykan osoykan merged commit da5485d into main Oct 20, 2025
5 checks passed
@renovate renovate bot deleted the renovate/all-minor-patch branch October 20, 2025 07:06
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants