Repository navigation
build(deps): bump org.apache.directory.api:api-util from 2.1.8 to 2.1.9 - #20534
dependabot[bot] wants to merge 1 commit into
Conversation
Bumps [org.apache.directory.api:api-util](https://github.com/apache/directory-ldap-api) from 2.1.8 to 2.1.9. - [Release notes](https://github.com/apache/directory-ldap-api/releases) - [Commits](apache/directory-ldap-api@2.1.8...2.1.9) --- updated-dependencies: - dependency-name: org.apache.directory.api:api-util dependency-version: 2.1.9 dependency-type: direct:production update-type: version-update:semver-patch ... Signed-off-by: dependabot[bot] <support@github.com>
FrankChen021
left a comment
There was a problem hiding this comment.
This is an automated review by Codex GPT-5.6 Luna(Max).
Compatibility analysis
Dependency: org.apache.directory.api:api-util, source 2.1.8, target 2.1.9. ROUND_1 verdict: SAFE for the sole published transition and the target's cumulative effect on Druid. The complete published path is 2.1.8 -> 2.1.9, verified against Maven Central metadata; no intervening release exists. Published artifacts and the upstream comparison were reviewed.
API/ABI: all 47 api-util classes and existing public members remain; two Strings helpers are added. Runtime requirements remain Java 8 bytecode, with unchanged module and bundle identities. The upstream parsing, case-folding, integer deserialization, and ASN.1 OID fixes do not change a Druid-used path: Druid has no Directory API Java imports, and the dependency is provided in Parquet and absent from its runtime graph. Consequently Druid configuration, client contracts, serialization/wire behavior, and persisted data remain unaffected. Transitives api-i18n and api-asn1-api resolve together at 2.1.9; two renamed i18n enum constants have no Druid or api-util consumers. Commons Text remains 1.15.0 and Druid resolves SLF4J 2.0.20. Apache-2.0 license text is unchanged in api-util, and both target transitive artifacts carry that same license. OSGi export versions advance normally; Druid does not use the Directory OSGi bundles or expose their SPI as an extension contract.
Druid impact
Reviewed 1 of 1 changed files: root pom.xml changes only the managed api-util version. The relevant declaration is the provided dependency in extensions-core/parquet-extensions/pom.xml. Repository-wide Java/XML searches found no Directory API source call sites. No tracked production or test source changed. This updates the build dependency without altering Druid's runtime dependency graph or behavior.
Validation
- Complete PR diff and clean checkout verified at the supplied base/head commits;
git diff --checkpassed. - Published source and binary artifacts, parent/module POMs, manifests, class versions, public API signatures, and license contents compared.
- Narrow Parquet Maven dependency-tree checks passed, including verbose transitive resolution and a runtime-scope check with no Directory API entry.
- All 27 checks on this commit succeeded, including compilation, static and packaging checks, unit/QTest partitions, coverage, Docker tests, web checks, and CodeQL. No additional local test suite was run.
CI gate
Exact current head: d10d4a1a4f04219442feec4255d1711d3ea86b9e. Fresh reads confirm OPEN, non-draft, MERGEABLE, and CLEAN. The authoritative statusCheckRollup state is SUCCESS; complete pagination reports 27 CheckRuns, all COMPLETED/SUCCESS, and 0 StatusContexts. Every reported item succeeded; no failure or rerun required resolution.
Automation actions
No tracked files were changed, no commit was pushed, and no CI jobs were rerun by the automation. No merge was performed.
Bumps org.apache.directory.api:api-util from 2.1.8 to 2.1.9.
Commits
07ff47f[maven-release-plugin] prepare release 2.1.974a8622[maven-release-plugin] rollback the release of 2.1.92b04b5b[maven-release-plugin] prepare release 2.1.967a7047Revert back to 2.1.9-SNAPSGOTffffd3bMerge pull request #332 from apache/dependabot/maven/org.bouncycastle-bcpkix-...5f0426eMerge pull request #336 from apache/coheigea/mask09db4a4Merge remote-tracking branch 'refs/remotes/origin/master'608b005Fixed some javadoc that were breaking the mvn site phase46f1750Merge pull request #339 from apache/coheigea/sasl-bindebd634dMerge pull request #338 from apache/coheigea/avaDependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting
@dependabot rebase.Dependabot commands and options
You can trigger Dependabot actions by commenting on this PR:
@dependabot rebasewill rebase this PR@dependabot recreatewill recreate this PR, overwriting any edits that have been made to it@dependabot show <dependency name> ignore conditionswill show all of the ignore conditions of the specified dependency@dependabot ignore this major versionwill close this PR and stop Dependabot creating any more for this major version (unless you reopen the PR or upgrade to it yourself)@dependabot ignore this minor versionwill close this PR and stop Dependabot creating any more for this minor version (unless you reopen the PR or upgrade to it yourself)@dependabot ignore this dependencywill close this PR and stop Dependabot creating any more for this dependency (unless you reopen the PR or upgrade to it yourself)