From a7c57fb1d4df4af8be34b6fc030d5b6cd31e2ff5 Mon Sep 17 00:00:00 2001
From: "dependabot[bot]" <49699333+dependabot[bot]@users.noreply.github.com>
Date: Fri, 18 Nov 2022 13:49:14 +0100
Subject: [PATCH] Bump byte-buddy-dep from 1.12.18 to 1.12.19 in
/examples/distro (#7228)
Bumps [byte-buddy-dep](https://github.com/raphw/byte-buddy) from 1.12.18
to 1.12.19.
Release notes
Sourced from byte-buddy-dep's
releases.
Byte Buddy 1.12.19
- Avoid possible lock through circular class loading of
TypeDescription
subtypes.
- Avoid access error when using unsafe API on Java 17 with an active
security manager.
- Close URL class loader used in Gradle plugin.
Changelog
Sourced from byte-buddy-dep's
changelog.
Byte Buddy release notes
Commits
c93425a
[maven-release-plugin] prepare release byte-buddy-1.12.19
b1f4e9b
[release] New release
8d17e3a
Merge pull request #1359
from eyalkoren/protection-domain
c57139e
Using explicit ProtectionDomain in dynamically loaded classes
ff8be9a
Attempt cloning protection domain from accessible object to avoid
security ma...
6fe45f7
Make s in message optional.
9023501
Fix scope of summary variable.
02091f1
Update codeql-analysis.yml
628b6a9
Close class loader in Gradle plugin, if possible.
9a81856
Remove unused import.
- Additional commits viewable in compare
view
[](https://docs.github.com/en/github/managing-security-vulnerabilities/about-dependabot-security-updates#about-compatibility-scores)
You can trigger a rebase of this PR by commenting `@dependabot rebase`.
[//]: # (dependabot-automerge-start)
[//]: # (dependabot-automerge-end)
---
Dependabot commands and options
You can trigger Dependabot actions by commenting on this PR:
- `@dependabot rebase` will rebase this PR
- `@dependabot recreate` will recreate this PR, overwriting any edits
that have been made to it
- `@dependabot merge` will merge this PR after your CI passes on it
- `@dependabot squash and merge` will squash and merge this PR after
your CI passes on it
- `@dependabot cancel merge` will cancel a previously requested merge
and block automerging
- `@dependabot reopen` will reopen this PR if it is closed
- `@dependabot close` will close this PR and stop Dependabot recreating
it. You can achieve the same result by closing it manually
- `@dependabot ignore this major version` will close this PR and stop
Dependabot creating any more for this major version (unless you reopen
the PR or upgrade to it yourself)
- `@dependabot ignore this minor version` will close this PR and stop
Dependabot creating any more for this minor version (unless you reopen
the PR or upgrade to it yourself)
- `@dependabot ignore this dependency` will close this PR and stop
Dependabot creating any more for this dependency (unless you reopen the
PR or upgrade to it yourself)
Signed-off-by: dependabot[bot]
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
---
examples/distro/build.gradle | 2 +-
1 file changed, 1 insertion(+), 1 deletion(-)
diff --git a/examples/distro/build.gradle b/examples/distro/build.gradle
index 3cb67af459..0576f09611 100644
--- a/examples/distro/build.gradle
+++ b/examples/distro/build.gradle
@@ -33,7 +33,7 @@ subprojects {
opentelemetryJavaagent : "1.21.0-SNAPSHOT",
opentelemetryJavaagentAlpha: "1.21.0-alpha-SNAPSHOT",
- bytebuddy : "1.12.18",
+ bytebuddy : "1.12.19",
autoservice : "1.0.1",
junit : "5.9.1"
]