Title: Bump org.assertj:assertj-core from 3.27.3 to 3.27.7 by dependabot[bot] · Pull Request #226 · java-diff-utils/java-diff-utils · GitHub
Open Graph Title: Bump org.assertj:assertj-core from 3.27.3 to 3.27.7 by dependabot[bot] · Pull Request #226 · java-diff-utils/java-diff-utils
X Title: Bump org.assertj:assertj-core from 3.27.3 to 3.27.7 by dependabot[bot] · Pull Request #226 · java-diff-utils/java-diff-utils
Description: Bumps org.assertj:assertj-core from 3.27.3 to 3.27.7.
Release notes
Sourced from org.assertj:assertj-core's releases.
v3.27.7
🔒 Security
Core
Fix XXE vulnerability in isXmlEqualTo assertion (CVE-2026-24400)
See GHSA-rqfh-9r24-8c9r for details; many thanks to @wxt201 and @Song-Li for responsibly reporting it!
🚫 Deprecated
Core
Deprecate XmlStringPrettyFormatter with no replacement
🐛 Bug Fixes
Guava
Navigation to assertj-core or guava types from assertj-guava Javadoc site has unnecessary header #3478
🔨 Dependency Upgrades
Core
Upgrade to Byte Buddy 1.18.3
Upgrade to JUnit BOM 5.14.1
Guava
Upgrade to Guava 33.5.0-jre
v3.27.6
🐛 Bug Fixes
Core
Add missing export for org.assertj.core.annotation #3951
❤️ Contributors
Thanks to all the contributors who worked on this release:
@duponter
v3.27.5
⚡ Improvements
Core
ByteBuddy in AssertJ 3.27.4 not compatible with Java 25 #3946
... (truncated)
Commits
e840716 [maven-release-plugin] prepare release assertj-build-3.27.7
85ca7eb Deprecate XmlStringPrettyFormatter
77081dc Merge commit from fork
b68fc24 Bump github/codeql-action from 4.31.9 to 4.31.10 in the github-actions group ...
0cf5bb6 Bump kotlin.version from 2.1.0 to 2.2.21
d393ef1 Abort tests when symbolic links cannot be created (#3788)
2212433 Add IntelliJ custom inspection for test class names
5717d02 Update JetBrains icon
a8ec20b Add icon for JetBrains products
c05fb3d Bump Maven to 3.9.12 and Wrapper to 3.3.4
Additional commits viewable in compare view
Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting @dependabot rebase.
Dependabot commands and options
You can trigger Dependabot actions by commenting on this PR:
@dependabot rebase will rebase this PR
@dependabot recreate will recreate this PR, overwriting any edits that have been made to it
@dependabot merge will merge this PR after your CI passes on it
@dependabot squash and merge will squash and merge this PR after your CI passes on it
@dependabot cancel merge will cancel a previously requested merge and block automerging
@dependabot reopen will reopen this PR if it is closed
@dependabot close will close this PR and stop Dependabot recreating it. You can achieve the same result by closing it manually
@dependabot show
Open Graph Description: Bumps org.assertj:assertj-core from 3.27.3 to 3.27.7. Release notes Sourced from org.assertj:assertj-core's releases. v3.27.7 🔒 Security Core Fix XXE vulnerability in isXmlEqualTo assertion ...
X Description: Bumps org.assertj:assertj-core from 3.27.3 to 3.27.7. Release notes Sourced from org.assertj:assertj-core's releases. v3.27.7 🔒 Security Core Fix XXE vulnerability in isXmlEqualTo assert...
Opengraph URL: https://github.com/java-diff-utils/java-diff-utils/pull/226
X: @github
Domain: patch-diff.githubusercontent.com
| route-pattern | /:user_id/:repository/pull/:id/checks(.:format) |
| route-controller | pull_requests |
| route-action | checks |
| fetch-nonce | v2:95a881a5-6739-fbd0-89ce-9d1b13e47018 |
| current-catalog-service-hash | 87dc3bc62d9b466312751bfd5f889726f4f1337bdff4e8be7da7c93d6c00a25a |
| request-id | C158:98BCF:1375CCD:1AAF167:6980809D |
| html-safe-nonce | acc33cd2ea0d3c625a39ae9aa8246f05601e6c30092c041f5641814624c86c26 |
| visitor-payload | eyJyZWZlcnJlciI6IiIsInJlcXVlc3RfaWQiOiJDMTU4Ojk4QkNGOjEzNzVDQ0Q6MUFBRjE2Nzo2OTgwODA5RCIsInZpc2l0b3JfaWQiOiI1MDA4NDYzMDQ0NjkxMzk0NzE3IiwicmVnaW9uX2VkZ2UiOiJpYWQiLCJyZWdpb25fcmVuZGVyIjoiaWFkIn0= |
| visitor-hmac | 5b4aee976ef12acfb298b4b70067155df0e2c060c0aa32e35401f016d51c8c15 |
| hovercard-subject-tag | pull_request:3212203062 |
| github-keyboard-shortcuts | repository,pull-request-list,pull-request-conversation,pull-request-files-changed,checks,copilot |
| google-site-verification | Apib7-x98H0j5cPqHWwSMm6dNU4GmODRoqxLiDzdx9I |
| octolytics-url | https://collector.github.com/github/collect |
| analytics-location | / |
| fb:app_id | 1401488693436528 |
| apple-itunes-app | app-id=1477376905, app-argument=https://github.com/java-diff-utils/java-diff-utils/pull/226/checks |
| twitter:image | https://avatars.githubusercontent.com/in/29110?s=400&v=4 |
| twitter:card | summary_large_image |
| og:image | https://avatars.githubusercontent.com/in/29110?s=400&v=4 |
| og:image:alt | Bumps org.assertj:assertj-core from 3.27.3 to 3.27.7. Release notes Sourced from org.assertj:assertj-core's releases. v3.27.7 🔒 Security Core Fix XXE vulnerability in isXmlEqualTo assertion ... |
| og:site_name | GitHub |
| og:type | object |
| hostname | github.com |
| expected-hostname | github.com |
| None | 4590f1c00c56e5b3a3460b81e4236454a157a2159793b09a2ddee090670e75fb |
| turbo-cache-control | no-preview |
| go-import | github.com/java-diff-utils/java-diff-utils git https://github.com/java-diff-utils/java-diff-utils.git |
| octolytics-dimension-user_id | 40540835 |
| octolytics-dimension-user_login | java-diff-utils |
| octolytics-dimension-repository_id | 86663812 |
| octolytics-dimension-repository_nwo | java-diff-utils/java-diff-utils |
| octolytics-dimension-repository_public | true |
| octolytics-dimension-repository_is_fork | false |
| octolytics-dimension-repository_network_root_id | 86663812 |
| octolytics-dimension-repository_network_root_nwo | java-diff-utils/java-diff-utils |
| turbo-body-classes | logged-out env-production page-responsive full-width full-width-p-0 |
| disable-turbo | false |
| browser-stats-url | https://api.github.com/_private/browser/stats |
| browser-errors-url | https://api.github.com/_private/browser/errors |
| release | 242fda17fe105562f9eb7fe91a7a0dca07c527b3 |
| ui-target | full |
| theme-color | #1e2327 |
| color-scheme | light dark |
Links:
Viewport: width=device-width