Bump com.mchange:c3p0 from 0.11.2 to 0.12.0#133
Conversation
Bumps [com.mchange:c3p0](https://github.com/swaldman/c3p0) from 0.11.2 to 0.12.0. - [Changelog](https://github.com/swaldman/c3p0/blob/0.12.x/CHANGELOG) - [Commits](swaldman/c3p0@v0.11.2...v0.12.0) --- updated-dependencies: - dependency-name: com.mchange:c3p0 dependency-version: 0.12.0 dependency-type: direct:production ... Signed-off-by: dependabot[bot] <support@github.com>
|
I checked the changelings and this was a simple security patch which the author thinks should not be a breaking change. as all tests pass, I think this can be merged
|
Bumps com.mchange:c3p0 from 0.11.2 to 0.12.0.
Changelog
Sourced from com.mchange:c3p0's changelog.
... (truncated)
Commits
afbb946Bump version for c3p0-0.12.0 final.c5f2445Documentation updates, RELEASE_NOTES-0.12.0, cap CHANGELOG for c3p0-0.12.0.d0d1c50Modify MarshallUnmarshallDataSourcesJUnitTestCase to include C3P0 config when...a42833dUpdate mchange-commons-java version to 0.4.0.415662bClaude-generated tests of deserialization-gadget mitigations.69dab9cCHANGELOG and documentation updates.5cb3247Track changes to com.mchange.ser.naming, more flexible control of whether nam...9bef1f6Update CHANGELOG and docs to more accurately reflect the necessarily imperfec...c6f5d11Centralize some of the jndiName-remoteness testing code, gate mbean- and jbos...155be12Small documentation fixes.Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting
@dependabot rebase.Dependabot commands and options
You can trigger Dependabot actions by commenting on this PR:
@dependabot rebasewill rebase this PR@dependabot recreatewill recreate this PR, overwriting any edits that have been made to it@dependabot show <dependency name> ignore conditionswill show all of the ignore conditions of the specified dependency@dependabot ignore this major versionwill close this PR and stop Dependabot creating any more for this major version (unless you reopen the PR or upgrade to it yourself)@dependabot ignore this minor versionwill close this PR and stop Dependabot creating any more for this minor version (unless you reopen the PR or upgrade to it yourself)@dependabot ignore this dependencywill close this PR and stop Dependabot creating any more for this dependency (unless you reopen the PR or upgrade to it yourself)You can disable automated security fix PRs for this repo from the Security Alerts page.