Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Update dependency com.github.tomakehurst:wiremock to v2.35.2 #26

Open
wants to merge 1 commit into
base: master
Choose a base branch
from

Conversation

renovate[bot]
Copy link
Contributor

@renovate renovate bot commented Jun 22, 2023

This PR contains the following updates:

Package Change Age Adoption Passing Confidence
com.github.tomakehurst:wiremock (source) 2.23.2 -> 2.35.2 age adoption passing confidence

Warning

Some dependencies could not be looked up. Check the Dependency Dashboard for more information.


Release Notes

wiremock/wiremock (com.github.tomakehurst:wiremock)

v2.35.2

Compare Source

v2.35.1: - Security Release

Compare Source

🔒 This is a security release that addresses the following issues

NOTE: WireMock Studio, a proprietary distribution discontinued in 2022, is also affected by those issues and also affected by CVE-2023-39967 - Overall CVSS Score 8.6 - “Controlled and full-read SSRF through URL parameter when testing a request, webhooks and proxy mode”. The fixes will not be provided. The vendor recommends migrating to WireMock Cloud which is available as SaaS and private beta for on-premises deployments

Credits: @​W0rty, @​numacanedo, @​Mahoney, @​tomakehurst, @​oleg-nenashev

v2.35.0

Compare Source

Enhancements

  • Add a negative contains matcher - thanks Damian Orzepowski
  • Expose a Java API method for removing stubs by ID - thanks Patryk Fraczek
  • Document the import API in the OpenAPI doc - thanks to user i-whammy
  • Added the ability to restrict the addresses WireMock can proxy/record to, as a security measure.

Fixes

  • Strip Maven directories from the standalone JAR as some were appearing that weren't related to dependencies actually present, confusing scanning tools - thanks to user krageon
  • Dropped back to slf4j 1.7.36 and relocate it in the standalone JAR (ensuring 2.x users won't experience conflicts).

v2.34.0

Compare Source

This will be the final 2.x.x release and also the last to support Java 8.

Fixes

  • Fixed #​1689 - incorrect HTTP version header - thanks to user Poojitha
  • Fixed #​1882 - bug preventing matching of date/time query params/headers with custom format - thanks Klaas Dellschaft
  • #​1930 - Fixed a partial path traversal vulnerability in the file source code - thanks Jonathan Leitschuh
  • Fixed #​1783 - proxyUrlPrefixToRemove ignored when using a response definition transformer - thanks to user Ross-H-Projects
  • Fixed #​1872 - create a request entity for POST, PUT etc. proxied requests when a content-length header is present, regardless of whether the size is 0.
  • Fixed #​1946 - maths helper now supports epoch dates as inputs.

Enhancements

  • Added a public, non-static getScenarios() method allowing access to all scenarios.

All dependencies brought up to date including Jetty to 9.4.48.v20220622.

v2.33.2

Compare Source

WireMock 2.33.1 was accidentally released using Java 11 rather than 8, resulting in class incompatibilities in places.

This release is functionally identical but built using Java 8.

v2.33.0

Compare Source

This is primarily a maintenance release that brings all dependency versions up to date including a version of Jackson containing the fix for CVE-2020-36518.

Enhancements
  • Added the ability to set and reset a single scenario's state
  • Proxy will now send a request body for any request method.
  • CORS response headers are now passed back from proxy responses when stub CORS is disabled.
Performance
  • Improved performance of Request.getHeaders() - thanks Doug Roper.
  • Improved performance of response body JSON parsing - thanks also Doug Roper.

v2.32.0

Compare Source

Enhancements
  • Closes #​1614 - proper support for subclassing of the JUnit5 WireMockExtension
  • Add support for put/delete file to/from a subfolder (#​1087)
  • Closes #​956 - added the ability to fetch serve events for a specific stub ID
  • Added ability to query unmatched serve events
  • Added ability to verify requests using a custom matcher
  • Upgraded to Apache HTTP Client 5.x
  • Added WireMock.jsonResponse factory methods (#​1428)
  • #​745 Need proxyUrlPrefixToRemove for proxy context url mapping (#​1556)
  • Removed dependence on Conscrypt for ALPN and HTTP/2
  • Recognize multipart/related and multipart/mixed (#​1415)
  • Allow running Wiremock without HTTP Server (#​1572)
  • Allow standalone runner to fetch mappings from classpath (#​1592)
  • Added new command line parameters "--jetty-header-request-size" and "--jetty-header-response-size" for set a custom size of headers in Jetty. "--jetty-header-buffer-size" is deprecated.
Fixes
  • Closes #​1688 - fall back to HTTPS 1.1 only when no ALPN provider can be loaded
  • Fixed #​1643 - regression in date parsing preventing year and year/month only dates
  • #​1612 prevent applying scientific notation and rounding to big numbers by ObjectMapper (#​1613)
  • Fixed #​1608 and #​1585 - incorrect zoning of date/times in response templating when truncating
Code quality
  • Enforce license headers with Spotless
  • Enforce consistent code style with Spotless
  • Upgrade to Gradle 7 + some Gradle config cleanup (#​1639)
  • Convert AcceptanceTestBase to JUnit Jupiter to limit future violations (#​1669)
  • Enable WireMock to be built on Java 11 and 17
  • Drop JMock in favour of Mockito (#​1630)

v2.27.2

Compare Source

v2.27.1

Compare Source

v2.27.0

Compare Source

v2.26.3

Compare Source

v2.26.2

Compare Source

v2.26.1

Compare Source

v2.26.0

Compare Source

v2.25.1

Compare Source

v2.25.0

Compare Source

v2.24.1

Compare Source

v2.24.0

Compare Source


Configuration

📅 Schedule: Branch creation - At any time (no schedule defined), Automerge - At any time (no schedule defined).

🚦 Automerge: Disabled by config. Please merge this manually once you are satisfied.

Rebasing: Whenever PR becomes conflicted, or you tick the rebase/retry checkbox.

🔕 Ignore: Close this PR and you won't be reminded about this update again.


  • If you want to rebase/retry this PR, check this box

This PR was generated by Mend Renovate. View the repository job log.

@renovate renovate bot force-pushed the renovate/com.github.tomakehurst-wiremock-2.x branch from 3f27087 to ec4e526 Compare July 8, 2023 02:34
@renovate renovate bot force-pushed the renovate/com.github.tomakehurst-wiremock-2.x branch from ec4e526 to 1fd5778 Compare September 7, 2023 20:36
@renovate renovate bot changed the title Update dependency com.github.tomakehurst:wiremock to v2.33.2 Update dependency com.github.tomakehurst:wiremock to v2.35.1 Sep 7, 2023
@renovate renovate bot changed the title Update dependency com.github.tomakehurst:wiremock to v2.35.1 Update dependency com.github.tomakehurst:wiremock to v2.27.2 Sep 29, 2023
@renovate renovate bot force-pushed the renovate/com.github.tomakehurst-wiremock-2.x branch from 1fd5778 to 8f41ac8 Compare September 29, 2023 23:33
@renovate renovate bot changed the title Update dependency com.github.tomakehurst:wiremock to v2.27.2 Update dependency com.github.tomakehurst:wiremock to v2.35.1 Dec 4, 2023
@renovate renovate bot force-pushed the renovate/com.github.tomakehurst-wiremock-2.x branch from 8f41ac8 to a0a9a0f Compare December 4, 2023 03:00
@renovate renovate bot force-pushed the renovate/com.github.tomakehurst-wiremock-2.x branch from a0a9a0f to 427c95f Compare April 10, 2024 02:22
@renovate renovate bot changed the title Update dependency com.github.tomakehurst:wiremock to v2.35.1 Update dependency com.github.tomakehurst:wiremock to v2.35.2 Apr 10, 2024
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

Successfully merging this pull request may close these issues.

0 participants