Skip to content

Bump org.apache.maven.plugins:maven-surefire-plugin from 3.1.2 to 3.5.6 - #177

Closed
dependabot[bot] wants to merge 1 commit into
mainfrom
dependabot/maven/org.apache.maven.plugins-maven-surefire-plugin-3.5.6
Closed

Bump org.apache.maven.plugins:maven-surefire-plugin from 3.1.2 to 3.5.6#177
dependabot[bot] wants to merge 1 commit into
mainfrom
dependabot/maven/org.apache.maven.plugins-maven-surefire-plugin-3.5.6

Conversation

@dependabot

@dependabot dependabot Bot commented on behalf of github Jun 2, 2026

Copy link
Copy Markdown

Bumps org.apache.maven.plugins:maven-surefire-plugin from 3.1.2 to 3.5.6.

Release notes

Sourced from org.apache.maven.plugins:maven-surefire-plugin's releases.

3.5.6

🚀 New features and improvements

  • Introduce reportTestTimestamp option and include timestamp for test sets and test cases (#3261) (#3302) @​olamy

🐛 Bug Fixes

👻 Maintenance

📦 Dependency updates

3.5.5

🚀 New features and improvements

🐛 Bug Fixes

  • Use PowerShell instead of WMIC for detecting zombie process on Windows (#3258) @​jbliznak. Please note if you are using Windows with Java 8 and not PowerShell (you have options to: use Java 9+, install PowerShell or stay on Surefire 3.5.4)
  • Properly work with test failures caused during beforeAll phase (#3194) @​Frawless

📝 Documentation updates

  • Clarify how late placeholder replacement (@{...}) deals with (#3208) @​kwin

👻 Maintenance

... (truncated)

Commits
  • 25ea054 [maven-release-plugin] prepare release surefire-3.5.6
  • e5f374c Bump org.fusesource.jansi:jansi from 2.4.2 to 2.4.3
  • dadd55b Issue #2613 Debugging failsafe tests: Message 'Listening for transport dt_soc...
  • 39dd250 Bump commons-io:commons-io from 2.21.0 to 2.22.0
  • 2774273 Ensure that the statistics filename is calculated only once. (#3326) (#3327)
  • 0d5df8a 3.5.x/bug/cherry pick embedded mode its (#3328)
  • 04ad9a2 Use surefire 3.5.5 by project itself for testing
  • 37e8f69 Add flakes attribute to use in testsuite report (#3306) (#3308)
  • a970fef Introduce reportTestTimestamp option and include timestamp for test sets and ...
  • e838393 deploy 3.5.x branch to nexus
  • Additional commits viewable in compare view

Dependabot compatibility score

Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting @dependabot rebase.


Dependabot commands and options

You can trigger Dependabot actions by commenting on this PR:

  • @dependabot rebase will rebase this PR
  • @dependabot recreate will recreate this PR, overwriting any edits that have been made to it
  • @dependabot show <dependency name> ignore conditions will show all of the ignore conditions of the specified dependency
  • @dependabot ignore this major version will close this PR and stop Dependabot creating any more for this major version (unless you reopen the PR or upgrade to it yourself)
  • @dependabot ignore this minor version will close this PR and stop Dependabot creating any more for this minor version (unless you reopen the PR or upgrade to it yourself)
  • @dependabot ignore this dependency will close this PR and stop Dependabot creating any more for this dependency (unless you reopen the PR or upgrade to it yourself)

Bumps [org.apache.maven.plugins:maven-surefire-plugin](https://github.com/apache/maven-surefire) from 3.1.2 to 3.5.6.
- [Release notes](https://github.com/apache/maven-surefire/releases)
- [Commits](apache/maven-surefire@surefire-3.1.2...surefire-3.5.6)

---
updated-dependencies:
- dependency-name: org.apache.maven.plugins:maven-surefire-plugin
  dependency-version: 3.5.6
  dependency-type: direct:production
  update-type: version-update:semver-minor
...

Signed-off-by: dependabot[bot] <support@github.com>
@dependabot dependabot Bot added dependencies Pull requests that update a dependency file java Pull requests that update java code labels Jun 2, 2026
schenksj added a commit that referenced this pull request Jun 19, 2026
* chore(deps): consolidate Dependabot updates

Triage and apply the open Dependabot dependency PRs in a single change.

Maven (pom.xml):
- jackson-databind 2.15.2 -> 2.22.0 (#178)
- maven-surefire-plugin 3.1.2 -> 3.5.6 (#177)
- exec-maven-plugin 3.1.0 -> 3.6.3 (#175)
- test-dependencies group (#173): junit 5.10.0 -> 6.0.3,
  s3 2.21.29 -> 2.43.0, azure-storage-blob 12.25.0 -> 12.33.3,
  azure-identity 1.12.0 -> 1.18.2, azure-core 1.48.0 -> 1.57.1,
  testcontainers 1.19.0 -> 2.0.5, google-cloud-storage 2.29.1 -> 2.67.0,
  google-cloud-nio 0.127.12 -> 0.131.0, mockito 5.7.0 -> 5.23.0,
  iceberg 1.7.1 -> 1.10.1, and maven-{compiler,resources,jar,source,
  javadoc,gpg}-plugin + central-publishing-maven-plugin bumps.

Cargo (native):
- futures 0.3.31 -> 0.3.32 (#164)
- tokio 1.45 -> 1.50 (#166)
- lru 0.12 -> 0.16 (#167)
- sha2 0.10 -> 0.11 (#163)
- thiserror 1 -> 2 (#170)
- libc / moka lockfile bumps (#169, #165)

GitHub Actions:
- actions/checkout v4 -> v6 (#162)

Held back (incompatible, not applied):
- scala-library 2.13.12 -> 3.8.3 (#173 sub-update): Scala 2->3 major;
  s3mock_2.13 requires Scala 2.13. Kept at 2.13.12.
- arrow-array / arrow-buffer 57 -> 58 (#168, #172): arrow, arrow-schema
  and parquet remain at 57 (pinned transitively by delta-kernel 0.19 and
  the quickwit fork). Mixing arrow 57/58 fails to compile.
- object_store 0.12 -> 0.13 (#171): breaking API changes and coupling
  with delta-kernel 0.19 / quickwit which pin 0.12.

Verified: `cargo check` clean; `mvn test-compile` clean;
PythonParityTest + BooleanFieldTest pass under junit 6 / surefire 3.5.6.

Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>

* fix(deps): hold junit at 5.12.2 — 6.0.3 requires Java 17

JUnit 6.0.x raised its baseline to Java 17 (junit-jupiter-api class files
are bytecode 61). This project targets Java 11, and CI compiles with
JDK 11, so the test sources failed with "class file has wrong version
61.0, should be 55.0". It only passed locally because the dev machine
runs JDK 19.

Bump to 5.12.2 instead — the latest Java 8/11-compatible 5.x line (still
an upgrade from the original 5.10.0). Verified compiling and running
tests under JDK 11.

Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>

* test(txlog): serialize global-cache tests to fix parallel race

CI surfaced flaky failures in txlog::cache tests (e.g.
test_clear_all_caches_removes_all_entries, test_global_cache_stats).
Root cause is test cross-contamination, not a production bug: several
tests exercise the process-wide cache registry / global manifest cache,
and `clear_all_caches()` wipes that shared state. Under cargo's parallel
runner one test's clear races with another's get/put/stats.

Reproduced deterministically on the unmodified code at
`--test-threads=16`: 13/40 runs failed across test_global_cache_stats,
test_get_or_create_cache_reuse, test_global_manifest_cache and the
clear_all_caches tests. Serializing them on a shared mutex: 0/40.

The moka 0.12.13 -> 0.12.15 patch in this PR only shifted scheduling
enough to make CI hit a pre-existing latent race; production code is
sound (get_or_create_cache uses double-checked locking, the cache is
best-effort with TTL/LRU eviction so a flush racing a read is at worst a
miss, and the sole production caller is an explicit invalidate-all JNI
API).

Add a poison-tolerant mutex (lock_global_state) and guard the six tests
that touch global cache state. Local-instance tests still run in
parallel.

Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>

---------

Co-authored-by: Claude Opus 4.8 (1M context) <noreply@anthropic.com>
@schenksj

schenksj commented Jul 5, 2026

Copy link
Copy Markdown
Collaborator

Consolidated into #184

@schenksj schenksj closed this Jul 5, 2026
@dependabot @github

dependabot Bot commented on behalf of github Jul 5, 2026

Copy link
Copy Markdown
Author

OK, I won't notify you again about this release, but will get in touch when a new version is available. If you'd rather skip all updates until the next major or minor version, let me know by commenting @dependabot ignore this major version or @dependabot ignore this minor version. You can also ignore all major, minor, or patch releases for a dependency by adding an ignore condition with the desired update_types to your config file.

If you change your mind, just re-open this PR and I'll resolve any conflicts on it.

@dependabot
dependabot Bot deleted the dependabot/maven/org.apache.maven.plugins-maven-surefire-plugin-3.5.6 branch July 5, 2026 02:27
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

dependencies Pull requests that update a dependency file java Pull requests that update java code

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant