Skip to content

build(deps): bump the jdbc-drivers group across 1 directory with 3 updates - #927

Closed
dependabot[bot] wants to merge 1 commit into
mainfrom
dependabot/maven/jdbc-drivers-67e65dad02
Closed

dependabot[bot] wants to merge 1 commit into
mainfrom
dependabot/maven/jdbc-drivers-67e65dad02

Conversation

@dependabot

@dependabot dependabot Bot commented on behalf of github Aug 10, 2026 •

Copy link
Copy Markdown
Contributor

Bumps the jdbc-drivers group with 3 updates in the / directory: org.apache.derby:derby, com.oracle.database.jdbc:ojdbc8 and com.microsoft.sqlserver:mssql-jdbc.

Updates org.apache.derby:derby from 10.14.2.0 to 10.17.1.0

Updates com.oracle.database.jdbc:ojdbc8 from 19.3.0.0 to 23.26.3.0.0

Updates com.microsoft.sqlserver:mssql-jdbc from 7.2.1.jre8 to 13.6.0.jre8

Release notes

Sourced from com.microsoft.sqlserver:mssql-jdbc's releases.

[13.6.0] Stable Release

Added

  • Add FLOAT16 Vector Version Negotiation to the TVP Write Path #2997

    • What was added: Negotiated vector-version validation before writing VECTOR column metadata for table-valued parameters.
    • Who benefits: Applications sending vector columns through table-valued parameters.
    • Impact: Rejects all vectors on version 0 and FLOAT16 vectors on version 1 before data is written to the wire, with a clear driver error.
  • Port Legacy FX Non-AE Test Scenarios to JUnit #3008

    • What was added: Forty-eight legacyFx-tagged JUnit tests covering previously unported non-Always-Encrypted functional scenarios.
    • Who benefits: Contributors and CI validation pipelines.
    • Impact: Improves regression coverage while advancing retirement of the legacy FX test suite.
  • Add Cross-Driver Connection String Aliases for Unification #3011

    • What was added: Case-insensitive aliases for uid, trusted_connection, app, connectTimeout, columnEncryption, and quotedId, mapped to their canonical JDBC properties.
    • Who benefits: Applications sharing connection-string configuration across Microsoft data drivers.
    • Impact: Improves portability while preserving all existing JDBC property names and aliases.
  • Add getCurrentApplicationName to PerformanceLogCallback #3018

    • What was added: A default getCurrentApplicationName() method that exposes the publishing connection's applicationName to performance callbacks.
    • Who benefits: Applications using connection pools and performance-event correlation.
    • Impact: Allows events to be associated with a pool or application without breaking existing callback implementations.

Changed

  • Optimize MONEY, DECIMAL, and String Processing in the ResultSet Read Path #2991

    • What was changed: Removed intermediate allocations from MONEY/SMALLMONEY decoding, common BigDecimal encoding, short synchronous string reads, and NBCROW initialization.
    • Who benefits: Applications reading high-volume or wide result sets.
    • Impact: Reduces garbage-collection pressure and improves throughput while preserving decoded values and existing fallback behavior.
  • Validate Reflective Class Names for Connection Properties #3004

    • What was changed: Added Java binary class-name validation before reflectively loading classes specified by properties such as socketFactoryClass and accessTokenCallbackClass.
    • Who benefits: Applications configuring custom callback, socket-factory, or related reflective classes.
    • Impact: Malformed class names now fail early with a dedicated driver error instead of producing confusing reflective-loading failures.
  • Update Vector Tests for Server-Side FLOAT16/FLOAT32 Conversion #3005

    • What was changed: Updated and expanded vector tests for implicit and explicit conversion between FLOAT16 and FLOAT32 vector subtypes.
    • Who benefits: Contributors validating vector interoperability against servers supporting vector version 2.
    • Impact: Covers assignments, casts, conversions, bulk copy, routines, precision loss, nulls, and dimension mismatch behavior.
  • Adjust License File to Enable GitHub Detection #3010

    • What was changed: Normalized the MIT license text formatting.
    • Who benefits: Repository users and automated tooling.
    • Impact: Enables GitHub to detect and display the repository license; there is no runtime impact.
  • Suppress CodeQL False Positive for Protocol-Mandated MD5 #3014

    • What was changed: Documented and suppressed the CodeQL SM05136 finding for MD5 used by NTLM channel binding as required by MS-NLMP.
    • Who benefits: Contributors and security-scanning pipelines.
    • Impact: Reduces false-positive security findings without changing authentication behavior.

... (truncated)

Commits

Note
Automatic rebases have been disabled on this pull request as it has been open for over 30 days.

@dependabot dependabot Bot added dependencies Pull requests that update a dependency file java Pull requests that update java code labels Aug 10, 2026
@dependabot
dependabot Bot force-pushed the dependabot/maven/jdbc-drivers-67e65dad02 branch 2 times, most recently from 65958dc to 18e52d8 Compare August 22, 2026 02:32
@dependabot
dependabot Bot force-pushed the dependabot/maven/jdbc-drivers-67e65dad02 branch 2 times, most recently from 09e4bd7 to efef043 Compare September 7, 2026 21:28
@dependabot
dependabot Bot force-pushed the dependabot/maven/jdbc-drivers-67e65dad02 branch from efef043 to 20e9772 Compare September 10, 2026 17:11
@coderabbitai

coderabbitai Bot commented Sep 10, 2026 •

Copy link
Copy Markdown

Important

Review skipped

Bot user detected.

To trigger a single review, invoke the @coderabbitai review command.

⚙️ Run configuration

Configuration used: Repository: dbunit/dbunit-extension/.coderabbit.yml

Review profile: ASSERTIVE

Plan: Advanced

Run ID: 0856ba43-9ab0-46eb-8152-cd98c519cb2a

You can disable this status message by setting the reviews.review_status to false in the CodeRabbit configuration file.

Use the checkbox below for a quick retry:

  • 🔍 Trigger review

Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out.

❤️ Share

Comment @coderabbitai help to get the list of available commands.

@dependabot
dependabot Bot force-pushed the dependabot/maven/jdbc-drivers-67e65dad02 branch from 20e9772 to 577481d Compare September 12, 2026 02:33
…dates

Bumps the jdbc-drivers group with 3 updates in the / directory: org.apache.derby:derby, com.oracle.database.jdbc:ojdbc8 and [com.microsoft.sqlserver:mssql-jdbc](https://github.com/Microsoft/mssql-jdbc).


Updates `org.apache.derby:derby` from 10.14.2.0 to 10.17.1.0

Updates `com.oracle.database.jdbc:ojdbc8` from 19.3.0.0 to 23.26.3.0.0

Updates `com.microsoft.sqlserver:mssql-jdbc` from 7.2.1.jre8 to 13.6.0.jre8
- [Release notes](https://github.com/Microsoft/mssql-jdbc/releases)
- [Changelog](https://github.com/microsoft/mssql-jdbc/blob/main/CHANGELOG.md)
- [Commits](https://github.com/Microsoft/mssql-jdbc/commits)

---
updated-dependencies:
- dependency-name: com.microsoft.sqlserver:mssql-jdbc
  dependency-version: 13.4.0.jre8
  dependency-type: direct:development
  update-type: version-update:semver-major
  dependency-group: jdbc-drivers
- dependency-name: com.oracle.database.jdbc:ojdbc8
  dependency-version: 23.26.3.0.0
  dependency-type: direct:production
  update-type: version-update:semver-major
  dependency-group: jdbc-drivers
- dependency-name: org.apache.derby:derby
  dependency-version: 10.17.1.0
  dependency-type: direct:development
  update-type: version-update:semver-minor
  dependency-group: jdbc-drivers
...

Signed-off-by: dependabot[bot] <support@github.com>
@dependabot
dependabot Bot force-pushed the dependabot/maven/jdbc-drivers-67e65dad02 branch from 577481d to 1cc7532 Compare September 19, 2026 02:32
@jeffjensen jeffjensen closed this Sep 20, 2026
@dependabot @github

dependabot Bot commented on behalf of github Sep 20, 2026

Copy link
Copy Markdown
Contributor Author

This pull request was built based on a group rule. Closing it will not ignore any of these versions in future pull requests.

To ignore these dependencies, configure ignore rules in dependabot.yml

@dependabot
dependabot Bot deleted the dependabot/maven/jdbc-drivers-67e65dad02 branch September 20, 2026 18:13
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

dependencies Pull requests that update a dependency file java Pull requests that update java code

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant