@@ -56,16 +56,16 @@ SPDX-License-Identifier: MIT
5656 <properties >
5757 <sonar .organization>bernardladenthin</sonar .organization>
5858 <jspecify .version>1.0.1</jspecify .version>
59- <lombok .version>1.18.46 </lombok .version>
59+ <lombok .version>1.18.48 </lombok .version>
6060 <errorprone .version>2.50.0</errorprone .version>
61- <nullaway .version>0.14.0 </nullaway .version>
61+ <nullaway .version>0.14.1 </nullaway .version>
6262 <!-- Checker Framework: the processor AND the checker-qual qualifiers it resolves.
6363 Both run on the build JDK and neither ships (checker-qual is provided scope), so
6464 this tracks the newest release. -->
65- <checker .version>4.2.2 </checker .version>
65+ <checker .version>4.2.3 </checker .version>
6666 <jackson .version>2.22.2</jackson .version>
6767 <reactor .version>3.8.7</reactor .version>
68- <slf4j .version>2.0.18 </slf4j .version>
68+ <slf4j .version>2.0.19 </slf4j .version>
6969 <logback .version>1.6.3</logback .version>
7070 <animal-sniffer .version>1.27</animal-sniffer .version>
7171 <junit .version>6.1.3</junit .version>
@@ -90,10 +90,10 @@ SPDX-License-Identifier: MIT
9090 section "jqwik prompt-injection in test output" for full context. -->
9191 <jqwik .version>1.9.3</jqwik .version>
9292 <archunit .version>1.5.0</archunit .version>
93- <spotbugs .version>4.10.4.0 </spotbugs .version>
93+ <spotbugs .version>4.10.4.1 </spotbugs .version>
9494 <fb-contrib .version>7.7.4</fb-contrib .version>
9595 <findsecbugs .version>1.14.0</findsecbugs .version>
96- <spotless .version>3.10.1 </spotless .version>
96+ <spotless .version>3.10.2 </spotless .version>
9797 <palantir-java-format .version>2.97.0</palantir-java-format .version>
9898 <project .build.sourceEncoding>UTF-8</project .build.sourceEncoding>
9999 <project .build.outputTimestamp>2026-09-01T07:57:45Z</project .build.outputTimestamp>
@@ -199,7 +199,7 @@ SPDX-License-Identifier: MIT
199199 org.checkerframework.framework.qual.DoesNotUnrefineReceiver". Processor and
200200 qualifiers must share a major version.
201201
202- provided scope resolves both constraints at once: 4.2.2 is on the compile
202+ provided scope resolves both constraints at once: 4.2.3 is on the compile
203203 classpath where the checker needs it, and provided is excluded from consumers'
204204 transitive graph AND from the fat jar (jar-with-dependencies takes scope
205205 runtime), so no checker-qual class of any version reaches a consumer's JVM.
@@ -349,7 +349,7 @@ SPDX-License-Identifier: MIT
349349 <plugin >
350350 <groupId >io.github.git-commit-id</groupId >
351351 <artifactId >git-commit-id-maven-plugin</artifactId >
352- <version >10.0.0 </version >
352+ <version >10.0.1 </version >
353353 </plugin >
354354 <plugin >
355355 <groupId >org.apache.maven.plugins</groupId >
@@ -359,7 +359,7 @@ SPDX-License-Identifier: MIT
359359 <plugin >
360360 <groupId >org.apache.maven.plugins</groupId >
361361 <artifactId >maven-compiler-plugin</artifactId >
362- <version >3.15 .0</version >
362+ <version >3.16 .0</version >
363363 </plugin >
364364 <plugin >
365365 <groupId >org.apache.maven.plugins</groupId >
@@ -389,7 +389,7 @@ SPDX-License-Identifier: MIT
389389 <plugin >
390390 <groupId >org.apache.maven.plugins</groupId >
391391 <artifactId >maven-surefire-plugin</artifactId >
392- <version >3.5.6 </version >
392+ <version >3.6.0 </version >
393393 <configuration >
394394 <!--
395395 Tests in the `vmlens` package are meaningful only when run
0 commit comments