Skip to content

Bump org.apache.jackrabbit:jackrabbit-webdav from 2.14.4 to 2.22.3#856

Open
dependabot[bot] wants to merge 1 commit intomasterfrom
dependabot/maven/org.apache.jackrabbit-jackrabbit-webdav-2.22.3
Open

Bump org.apache.jackrabbit:jackrabbit-webdav from 2.14.4 to 2.22.3#856
dependabot[bot] wants to merge 1 commit intomasterfrom
dependabot/maven/org.apache.jackrabbit-jackrabbit-webdav-2.22.3

Conversation

@dependabot
Copy link
Contributor

@dependabot dependabot bot commented on behalf of github Jan 19, 2026

Bumps org.apache.jackrabbit:jackrabbit-webdav from 2.14.4 to 2.22.3.

Changelog

Sourced from org.apache.jackrabbit:jackrabbit-webdav's changelog.

Changes in Jackrabbit 2.22.3

Sub-task

[JCR-5160] - Create jacoco reports compliant with SonarQube Cloud
[JCR-5172] - Exclude test sources from SonarQube analysis
[JCR-5173] - Create aggregate jacoco report
[JCR-5174] - Exclude jackrabbit-jcr-tests from coverage calculation

Bug

[JCR-5141] - Deprecate org.apache.jackrabbit.commons.json
[JCR-5196] - Some test classes are not executed by default because they haven't been added to a test suite

Improvement

[JCR-5154] - Replace deprecated call of Class.newInstance()

Task

[JCR-5132] - webapp: update tomcat dependency to 9.0.104
[JCR-5133] - Update easymock dependency to 5.5.0
[JCR-5140] - Improve support for generating namespace prefixes
[JCR-5148] - remove (comment out) mysql test profile
[JCR-5156] - webapp: update tomcat dependency to 9.0.112
[JCR-5163] - Update commons file-upload dependency to 1.6.0
[JCR-5175] - Update Mockito dependency to 5.20.0
[JCR-5176] - Update commons-io dependency to 2.21.0
[JCR-5178] - Update easymock dependency to 5.6.0
[JCR-5182] - Update pax-exam test dependency to 4.14.0
[JCR-5183] - Vote Template should be clear about the fact that running the check script in "sh" will not work
[JCR-5185] - Update oak-jackrabbit-api.version.implemented in trunk to Oak 1.86.0
[JCR-5187] - Update commons-cli dependency to 1.11.0
[JCR-5188] - Update h2db dependency to 2.3.232
[JCR-5189] - update Jetty to 9.4.58.v20250814
[JCR-5190] - webapp: bump htmlunit to 4.19.0
[JCR-5191] - remove JEXL dependency
[JCR-5192] - update aws java sdk version to 1.12.791
[JCR-5193] - update Apache parent pom to version 35
[JCR-5195] - Utilities for 'safe' creation of XML document builders
[JCR-5197] - cleanup o.a.j.util.Base64 and update Javadoc
[JCR-5200] - Update h2db dependency to 2.4.240
[JCR-5201] - Update oak-jackrabbit-api.version.implemented in trunk to Oak 1.88.0

For more detailed information about all the changes in this and other Jackrabbit releases, please see the Jackrabbit issue tracker at

https://issues.apache.org/jira/browse/JCR

... (truncated)

Commits
  • 5dce857 [maven-release-plugin] prepare release jackrabbit-2.22.3
  • b6da2b3 JCR-5214: Release Jackrabbit 2.22.3 - Candidate Release Notes (#321)
  • d241fae JCR-5174 Use SonarQube path patterns which should work with multimodule
  • d96fb2f trivial: Remove prerequisites from POM
  • 0fbedf4 JCR-5174 Exclude jackrabbit-jcr-tests from coverage calculation
  • dadb919 JCR-5173 Create aggregated coverage report
  • 7a90a41 Fix a typo: @​peop -> @​prop
  • be3a79f JCR-5160 Generate Jacoco Report in default location to be picked up by
  • 76c7cd0 JCR-5174 Exclude jackrabbit-jcr-tests from coverage calculation
  • ace0186 JCR-5201: Update oak-jackrabbit-api.version.implemented in trunk to Oak 1.88....
  • Additional commits viewable in compare view

Dependabot compatibility score

Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting @dependabot rebase.


Dependabot commands and options

You can trigger Dependabot actions by commenting on this PR:

  • @dependabot rebase will rebase this PR
  • @dependabot recreate will recreate this PR, overwriting any edits that have been made to it
  • @dependabot merge will merge this PR after your CI passes on it
  • @dependabot squash and merge will squash and merge this PR after your CI passes on it
  • @dependabot cancel merge will cancel a previously requested merge and block automerging
  • @dependabot reopen will reopen this PR if it is closed
  • @dependabot close will close this PR and stop Dependabot recreating it. You can achieve the same result by closing it manually
  • @dependabot show <dependency name> ignore conditions will show all of the ignore conditions of the specified dependency
  • @dependabot ignore this major version will close this PR and stop Dependabot creating any more for this major version (unless you reopen the PR or upgrade to it yourself)
  • @dependabot ignore this minor version will close this PR and stop Dependabot creating any more for this minor version (unless you reopen the PR or upgrade to it yourself)
  • @dependabot ignore this dependency will close this PR and stop Dependabot creating any more for this dependency (unless you reopen the PR or upgrade to it yourself)

Bumps [org.apache.jackrabbit:jackrabbit-webdav](https://github.com/apache/jackrabbit) from 2.14.4 to 2.22.3.
- [Changelog](https://github.com/apache/jackrabbit/blob/jackrabbit-2.22.3/RELEASE-NOTES.txt)
- [Commits](apache/jackrabbit@jackrabbit-2.14.4...jackrabbit-2.22.3)

---
updated-dependencies:
- dependency-name: org.apache.jackrabbit:jackrabbit-webdav
  dependency-version: 2.22.3
  dependency-type: direct:production
  update-type: version-update:semver-minor
...

Signed-off-by: dependabot[bot] <support@github.com>
@dependabot dependabot bot added dependencies Pull requests that update a dependency file java Pull requests that update Java code labels Jan 19, 2026
@Bukama
Copy link
Contributor

Bukama commented Feb 6, 2026

Rule 0: org.codehaus.mojo.extraenforcer.dependencies.EnforceBytecodeVersion failed with message:
Found Banned Dependency: org.apache.jackrabbit:jackrabbit-webdav:jar:2.22.3

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

dependencies Pull requests that update a dependency file java Pull requests that update Java code

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant