Skip to content

deps(maven): bump com.diffplug.spotless:spotless-maven-plugin from 3.4.0 to 3.5.1#11

Merged
github-actions[bot] merged 1 commit into
mainfrom
dependabot/maven/com.diffplug.spotless-spotless-maven-plugin-3.5.0
May 20, 2026
Merged

deps(maven): bump com.diffplug.spotless:spotless-maven-plugin from 3.4.0 to 3.5.1#11
github-actions[bot] merged 1 commit into
mainfrom
dependabot/maven/com.diffplug.spotless-spotless-maven-plugin-3.5.0

Conversation

@dependabot
Copy link
Copy Markdown
Contributor

@dependabot dependabot Bot commented on behalf of github May 15, 2026

Bumps com.diffplug.spotless:spotless-maven-plugin from 3.4.0 to 3.5.1.

Release notes

Sourced from com.diffplug.spotless:spotless-maven-plugin's releases.

Maven Plugin v3.5.1

Fixed

  • <licenseHeader> with <yearMode>SET_FROM_GIT</yearMode> no longer runs git log through a shell, eliminating a shell-injection vector when formatting files whose names contain shell metacharacters.
  • Bump transitive plexus-utils 4.0.2 -> 4.0.3 to address CVE-2025-67030. (#2919)

Maven Plugin v3.5.0

Added

  • <scalafmt> now reads the version from the version field in the scalafmt config file when no <version> is explicitly set, falling back to the built-in default only if neither is available. (#2922)
  • Add <toml> format type with <versionCatalog> step for formatting and sorting Gradle version catalog files. (#2916)
  • Add <javaparserVersion> option to <cleanthat>, allowing users to override the JavaParser version pulled in transitively by Cleanthat. (#2903)
  • Add a expandWildcardImports API for java (#2829)

Fixed

  • Preserve case of JDBI named bind params that collide with SQL keywords (e.g. :limit, :offset) in the DBeaver SQL formatter. (#2899)
  • The -Dspotless.ratchetFrom=... user property now takes priority over <ratchetFrom> configured in the plugin or in individual formatters, instead of being overridden by them. (#2896, fixes #2842)
  • Fix non-idempotent formatting when importOrder() is combined with greclipse(): a single catch-all group no longer strips blank lines that greclipse() independently inserted between import groups. (#2914)

Changes

  • Fix expandWildcardImports failing on JDK XML types such as org.xml.sax.InputSource. (#2921)
  • Use Eclipse JDT's collator-based comparison when sorting Java members to better match Eclipse save actions. (#2920)
  • Bump default cleanthat version 2.24 -> 2.25. (#2903)
  • Bump default eclipse-jdt version from 4.35 to 4.39. (#2912)
Commits

@dependabot dependabot Bot added dependencies Pull requests that update a dependency file java Pull requests that update java code labels May 15, 2026
@dependabot dependabot Bot changed the title deps(maven): bump com.diffplug.spotless:spotless-maven-plugin from 3.4.0 to 3.5.0 deps(maven): bump com.diffplug.spotless:spotless-maven-plugin from 3.4.0 to 3.5.1 May 20, 2026
@dependabot dependabot Bot force-pushed the dependabot/maven/com.diffplug.spotless-spotless-maven-plugin-3.5.0 branch from 8f895e9 to 8369113 Compare May 20, 2026 16:23
@github-actions github-actions Bot enabled auto-merge (squash) May 20, 2026 16:23
@dependabot dependabot Bot force-pushed the dependabot/maven/com.diffplug.spotless-spotless-maven-plugin-3.5.0 branch from 8369113 to 9248eea Compare May 20, 2026 16:29
Bumps [com.diffplug.spotless:spotless-maven-plugin](https://github.com/diffplug/spotless) from 3.4.0 to 3.5.1.
- [Release notes](https://github.com/diffplug/spotless/releases)
- [Changelog](https://github.com/diffplug/spotless/blob/main/CHANGES.md)
- [Commits](diffplug/spotless@maven/3.4.0...maven/3.5.1)

---
updated-dependencies:
- dependency-name: com.diffplug.spotless:spotless-maven-plugin
  dependency-version: 3.5.0
  dependency-type: direct:production
  update-type: version-update:semver-minor
...

Signed-off-by: dependabot[bot] <support@github.com>
@dependabot dependabot Bot force-pushed the dependabot/maven/com.diffplug.spotless-spotless-maven-plugin-3.5.0 branch from 9248eea to 8b7bd45 Compare May 20, 2026 16:33
@github-actions github-actions Bot merged commit ea5099d into main May 20, 2026
11 checks passed
@dependabot dependabot Bot deleted the dependabot/maven/com.diffplug.spotless-spotless-maven-plugin-3.5.0 branch May 20, 2026 16:36
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

dependencies Pull requests that update a dependency file java Pull requests that update java code

Projects

None yet

Development

Successfully merging this pull request may close these issues.

0 participants