Skip to content

Upgrade spotbugs and pitest-maven to latest patch versions#220

Merged
bernardladenthin merged 2 commits into
mainfrom
claude/loving-goldberg-nlpw2m
Jun 10, 2026
Merged

Upgrade spotbugs and pitest-maven to latest patch versions#220
bernardladenthin merged 2 commits into
mainfrom
claude/loving-goldberg-nlpw2m

Conversation

@bernardladenthin

Copy link
Copy Markdown
Owner

Summary

  • Upgrade spotbugs from 4.9.8.3 to 4.9.8.4
  • Upgrade pitest-maven from 1.25.3 to 1.25.4
  • Update documentation and Dependabot configuration to enforce jqwik version pinning

Test plan

  • CI is green on this branch
  • Docs updated where applicable

Related issues / PRs

None

Checklist

  • I have read CONTRIBUTING.md and CODE_OF_CONDUCT.md
  • My commits follow Conventional Commits
  • No security-sensitive changes

Notes

The spotbugs and pitest-maven upgrades are routine patch version bumps with no breaking changes. The Dependabot configuration change adds an ignore rule to block all net.jqwik updates (every version, including patches) due to the anti-AI prompt-injection policy documented in the README. This prevents accidental upgrades past jqwik 1.9.3, which is the last pre-disclosure release before the library added prompt-injection strings targeting AI agents in test output.

https://claude.ai/code/session_01XEjgThAas1gQV65HK6kSqM

@bernardladenthin bernardladenthin merged commit a345764 into main Jun 10, 2026
4 of 9 checks passed
@bernardladenthin bernardladenthin deleted the claude/loving-goldberg-nlpw2m branch June 10, 2026 11:24
@sonarqubecloud

Copy link
Copy Markdown

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants