Skip to content

Conversation

@dependabot
Copy link
Contributor

@dependabot dependabot bot commented on behalf of github Jan 16, 2026

JDK21

Bumps io.quarkus:quarkus-bom from 3.17.5 to 3.30.6.

Release notes

Sourced from io.quarkus:quarkus-bom's releases.

3.30.6

Major changes

  • #51792 - Exclude org.lz4:lz4-java in favor of at.yawk.lz4:lz4-java

Complete changelog

  • #51637 - Dynamic Logger names linger in memory until OOME
  • #51705 - quarkus-oidc throws NPE if the JWT's header is malformed
  • #51723 - Add a warning about using dynamic names for Loggers
  • #51724 - Add PATCH to HttpMethod in Route.java
  • #51725 - Fix invalid JWT headers NPE during delayed JWK resolution
  • #51728 - Fix NPE when emitting runtime JFR event from shutdown hook
  • #51729 - Add PATCH to HttpMethod in io.quarkus.vertx.web.Route
  • #51749 - Return failure for invalid basic authorization
  • #51781 - Fix grammar
  • #51792 - Exclude org.lz4:lz4-java in favor of at.yawk.lz4:lz4-java

3.30.5

Complete changelog

  • #43134 - OpenTelemetry: MDC context disappears on ManagedExecutor thread
  • #51195 - Environment variable KAFKA_TLS_CONFIGURATION_NAME does not take effect
  • #51607 - Swagger UI does not send Authorization header when using @AuthorizationPolicy on REST resource class instead of @Authenticated
  • #51625 - Improve Logging guide regarding logging adapters
  • #51626 - Send Authorization header from Swagger UI for methods secured with @AuthorizationPolicy and reflect policies in OpenAPI document
  • #51638 - Fix issue with @JsonView support in REST Client
  • #51641 - Fix OTel MDC context set
  • #51642 - quarkus-maven-plugin generate-code-tests fails with some mvn -f paths
  • #51645 - Upgrade to Apache Maven 3.9.12
  • #51648 - Bump to Maven 3.9.12
  • #51664 - Make sure the project directory is normalized in LocalProject
  • #51666 - Do not enforce request and absolute OIDC redirect-path match
  • #51668 - When using InterceptionProxy to create multiple beans of the same type IllegalStateException: Multiple GeneratedClassBuildItem were produced for the same classes
  • #51684 - ArC: InterceptionProxy - add bean id to the name of generated subclass
  • #51686 - Fix KAFKA_TLS_CONFIGURATION_NAME environment variable not being recognized
  • #51688 - Potential memory leak with @QuarkusMainTest for CLI application
  • #51695 - Avoid logging on success in ContainerRuntimeUtil
  • #51712 - Fix two class loader-related leaks, one in Jackson, the other in QuarkusClassLoader

3.30.4

Complete changelog

  • #50814 - Changing compose-devservices.yml does not invalidate Gradle cache
  • #51045 - Port 8080 already used using quarkus-amazon-lambda and quarkus-observability-devservices-*
  • #51107 - JBoss Threads update to version 3.9.2, allows minor cleanup
  • #51139 - Upgrade LGTM to 0.11.17
  • #51326 - Running mvn dependency:tree quarkus:dev gives [WARNING] Failed to locate plugin for dependency:tree

... (truncated)

Commits
  • df4d144 [RELEASE] - Bump version to 3.30.6
  • 854d1d0 Merge pull request #51816 from gsmet/3.30.6-backports-1
  • 4a70849 Fix typos in kubernetes-config documentation
  • 8370242 Update Njord to 0.9.2
  • 1107f29 Exclude org.lz4:lz4-java in favor of at.yawk.lz4:lz4-java
  • 56dc215 Add note about REST Client connection pool size
  • c63da30 fix grammar
  • 67eeab4 feat: add PATCH to HttpMethod in io.quarkus.vertx.web.Route
  • 9e12e34 Return failure instead when basic authorization header is invalid
  • f70ef7e Fix NPE when emitting runtime JFR event from shutdown hook
  • Additional commits viewable in compare view

Dependabot compatibility score

You can trigger a rebase of this PR by commenting @dependabot rebase.


Dependabot commands and options

You can trigger Dependabot actions by commenting on this PR:

  • @dependabot rebase will rebase this PR
  • @dependabot recreate will recreate this PR, overwriting any edits that have been made to it
  • @dependabot merge will merge this PR after your CI passes on it
  • @dependabot squash and merge will squash and merge this PR after your CI passes on it
  • @dependabot cancel merge will cancel a previously requested merge and block automerging
  • @dependabot reopen will reopen this PR if it is closed
  • @dependabot close will close this PR and stop Dependabot recreating it. You can achieve the same result by closing it manually
  • @dependabot show <dependency name> ignore conditions will show all of the ignore conditions of the specified dependency
  • @dependabot ignore this major version will close this PR and stop Dependabot creating any more for this major version (unless you reopen the PR or upgrade to it yourself)
  • @dependabot ignore this minor version will close this PR and stop Dependabot creating any more for this minor version (unless you reopen the PR or upgrade to it yourself)
  • @dependabot ignore this dependency will close this PR and stop Dependabot creating any more for this dependency (unless you reopen the PR or upgrade to it yourself)

@dependabot dependabot bot added dependencies Pull requests that update a dependency file java Pull requests that update java code labels Jan 16, 2026
@tomjenkinson
Copy link
Member

@dependabot rebase

Bumps [io.quarkus:quarkus-bom](https://github.com/quarkusio/quarkus) from 3.17.5 to 3.30.6.
- [Release notes](https://github.com/quarkusio/quarkus/releases)
- [Commits](quarkusio/quarkus@3.17.5...3.30.6)

---
updated-dependencies:
- dependency-name: io.quarkus:quarkus-bom
  dependency-version: 3.30.6
  dependency-type: direct:production
  update-type: version-update:semver-minor
...

Signed-off-by: dependabot[bot] <support@github.com>
@dependabot dependabot bot force-pushed the dependabot/maven/io.quarkus-quarkus-bom-3.30.6 branch from 7d29d7e to a62a0d8 Compare January 19, 2026 13:04
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

dependencies Pull requests that update a dependency file java Pull requests that update java code

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants