From e06143e15aac05720d8b8fde3ef97073c4eaacff Mon Sep 17 00:00:00 2001 From: "dependabot[bot]" <49699333+dependabot[bot]@users.noreply.github.com> Date: Fri, 4 Sep 2026 11:28:13 +0100 Subject: [PATCH 1/5] Bump antora from 3.2.0-rc.3 to 3.2.0 in /docs (#680) Bumps [antora](https://gitlab.com/antora/antora/tree/HEAD/packages/antora) from 3.2.0-rc.3 to 3.2.0. - [Changelog](https://gitlab.com/antora/antora/blob/main/CHANGELOG.adoc) - [Commits](https://gitlab.com/antora/antora/compare/v3.2.0-rc.3...v3.2.0) --- updated-dependencies: - dependency-name: antora dependency-version: 3.2.0 dependency-type: direct:production update-type: version-update:semver-patch ... Signed-off-by: dependabot[bot] Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com> --- docs/package.json | 2 +- 1 file changed, 1 insertion(+), 1 deletion(-) diff --git a/docs/package.json b/docs/package.json index 253ac524..a45936ea 100644 --- a/docs/package.json +++ b/docs/package.json @@ -1,6 +1,6 @@ { "dependencies": { - "antora": "3.2.0-rc.3", + "antora": "3.2.0", "@antora/atlas-extension": "1.0.0-alpha.5", "@antora/collector-extension": "1.0.3", "@asciidoctor/tabs": "1.0.0-beta.6", From f8bf7ab47f697f7fba144380ed27d81f5ea08092 Mon Sep 17 00:00:00 2001 From: "dependabot[bot]" <49699333+dependabot[bot]@users.noreply.github.com> Date: Mon, 7 Sep 2026 09:46:30 +0000 Subject: [PATCH 2/5] Bump org.apache.ant:ant from 1.10.17 to 1.10.18 Bumps org.apache.ant:ant from 1.10.17 to 1.10.18. --- updated-dependencies: - dependency-name: org.apache.ant:ant dependency-version: 1.10.18 dependency-type: direct:production update-type: version-update:semver-patch ... Signed-off-by: dependabot[bot] --- pom.xml | 2 +- 1 file changed, 1 insertion(+), 1 deletion(-) diff --git a/pom.xml b/pom.xml index 61424f18..08054eb3 100644 --- a/pom.xml +++ b/pom.xml @@ -102,7 +102,7 @@ 0.0.11 true 3.2.10 - 1.10.17 + 1.10.18 ${project.basedir}/modules/ROOT/partials/_configprops.adoc .* generate-resources From 7c1753cdc26f6461f7cd1055677734939fa02795 Mon Sep 17 00:00:00 2001 From: Ryan Baxter Date: Fri, 4 Sep 2026 13:17:48 -0400 Subject: [PATCH 3/5] Make Spring Cloud builds reproducible --- pom.xml | 14 ++++++++++++++ spring-cloud-build-dependencies/pom.xml | 3 +++ spring-cloud-dependencies-parent/pom.xml | 3 +++ 3 files changed, 20 insertions(+) diff --git a/pom.xml b/pom.xml index 08054eb3..ed6dc86a 100644 --- a/pom.xml +++ b/pom.xml @@ -24,6 +24,10 @@ @ UTF-8 UTF-8 + + 1980-02-01T00:00:00Z ${java.version} ${java.version} ${basedir} @@ -580,6 +584,16 @@ true yyyy-MM-dd'T'HH:mm:ssZ + + UTC + + + git.build.host + git.build.user.name + git.build.user.email + true ${project.build.outputDirectory}/git.properties diff --git a/spring-cloud-build-dependencies/pom.xml b/spring-cloud-build-dependencies/pom.xml index 3a6064e0..e0c26424 100644 --- a/spring-cloud-build-dependencies/pom.xml +++ b/spring-cloud-build-dependencies/pom.xml @@ -20,6 +20,9 @@ UTF-8 4.0.9-SNAPSHOT + + 1980-02-01T00:00:00Z 4.12.0 3.2.8 0.9.0 diff --git a/spring-cloud-dependencies-parent/pom.xml b/spring-cloud-dependencies-parent/pom.xml index beddb54a..00c94e3a 100644 --- a/spring-cloud-dependencies-parent/pom.xml +++ b/spring-cloud-dependencies-parent/pom.xml @@ -72,6 +72,9 @@ UTF-8 0.9.0 3.1.4 + + 1980-02-01T00:00:00Z https://github.com/spring-cloud From f82e8518329cf8140c7f145698774a2f61f56f00 Mon Sep 17 00:00:00 2001 From: "dependabot[bot]" <49699333+dependabot[bot]@users.noreply.github.com> Date: Tue, 15 Sep 2026 09:44:21 +0000 Subject: [PATCH 4/5] Bump org.codehaus.mojo:exec-maven-plugin from 3.6.3 to 3.6.4 Bumps [org.codehaus.mojo:exec-maven-plugin](https://github.com/mojohaus/exec-maven-plugin) from 3.6.3 to 3.6.4. - [Release notes](https://github.com/mojohaus/exec-maven-plugin/releases) - [Commits](https://github.com/mojohaus/exec-maven-plugin/compare/3.6.3...3.6.4) --- updated-dependencies: - dependency-name: org.codehaus.mojo:exec-maven-plugin dependency-version: 3.6.4 dependency-type: direct:production update-type: version-update:semver-patch ... Signed-off-by: dependabot[bot] --- pom.xml | 2 +- 1 file changed, 1 insertion(+), 1 deletion(-) diff --git a/pom.xml b/pom.xml index ed6dc86a..cbbafa27 100644 --- a/pom.xml +++ b/pom.xml @@ -71,7 +71,7 @@ 3.5.6 2.22.2 3.5.1 - 3.6.3 + 3.6.4 3.3.1 4.9.10 3.6.2 From 9ee76b6f410141f0df8de11f4e57214fceb21e2c Mon Sep 17 00:00:00 2001 From: Ryan Baxter Date: Thu, 17 Sep 2026 16:22:46 -0400 Subject: [PATCH 5/5] Exclude logback-classic from generate-configprops plugin dependency spring-cloud-build-docs is consumed via the jar-with-dependencies classifier, which already bundles a matched logback-classic/ logback-core pair. exec-maven-plugin's includePluginDependencies classpath merge also separately resolves the dependency's own unversioned logback-classic, landing an old, incompatible logback-classic/logback-core split across the uber jar and the separately-resolved thin jar. Depending on classpath ordering this intermittently fails generate-configprops with: java.lang.NoSuchMethodError: 'java.lang.ClassLoader ch.qos.logback.core.util.Loader.systemClassloaderIfNull(java.lang.ClassLoader)' Excluding logback-classic (and transitively logback-core) forces the classpath to rely solely on the bundled, self-consistent pair. --- pom.xml | 14 ++++++++++++++ 1 file changed, 14 insertions(+) diff --git a/pom.xml b/pom.xml index cbbafa27..9fc13e39 100644 --- a/pom.xml +++ b/pom.xml @@ -1248,6 +1248,20 @@ ${spring-cloud-build-docs-classifier} jar + + + + ch.qos.logback + logback-classic + +