aboutsummaryrefslogtreecommitdiff
diff options
context:
space:
mode:
authordependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>2023-09-06 15:11:28 -0700
committerGoogle Java Core Libraries <java-libraries-firehose+copybara@google.com>2023-09-06 15:12:36 -0700
commit903ffd084a0b1d99b02be71b61c95284ed1165a6 (patch)
tree954f21c991f2bb3bbb4ce369f5494e769c33dcba
parent905bb83c1bc25733507adb0ed1e7e1ac8bf26d5e (diff)
downloadauto-903ffd084a0b1d99b02be71b61c95284ed1165a6.tar.gz
Bump com.google.truth:truth from 1.1.3 to 1.1.5 in /service
Bumps [com.google.truth:truth](https://github.com/google/truth) from 1.1.3 to 1.1.5. <details> <summary>Release notes</summary> <p><em>Sourced from <a href="https://github.com/google/truth/releases">com.google.truth:truth's releases</a>.</em></p> <blockquote> <h2>1.1.5</h2> <ul> <li>Updated Truth to depend on <a href="https://github.com/google/guava/releases/tag/v32.0.1">Guava 32.0.1</a>. The previous Guava version, 32.0.0, contained a bug under Windows, which did not affect Truth's functionality but <a href="https://redirect.github.com/google/truth/issues/1137">could cause problems</a> for people who use Guava's I/O functionality in their codebase. Affected users can already manually update their Guava dependency to 32.0.1, but if they don't depend directly on Guava, they may find it easier to upgrade to this new Truth release instead.</li> <li>Fixed <code>IterableOfProtosSubject</code> to produce a proper failure message instead of NPE when the actual value is <code>null</code>.</li> </ul> <h2>1.1.4</h2> <ul> <li>Updated Truth to build with <code>-source 8 -target 8</code>. This means that it no longer runs under Java 7 VMs. It continues to run under Android, even old versions, for all apps that have <a href="https://developer.android.com/studio/write/java8-support#supported_features">enabled support for Java 8 language features</a>. (db5db2429)</li> <li>Updated Truth to depend on Guava 32.0.0. That release contains changes related to CVEs. Neither of the CVEs relates to any methods that are used by Truth, so this version bump is just about eliminating any warnings related to the old version and helping tools like Maven to select the newest version of Guava. (f8d4dbba8adc65effba70879d59a39da092dce51, 99b1df8852a25b5638590bea1b55a31ae536936d)</li> <li>Added support for <code>value of: method()</code> to <code>expect.that</code>, matching the existing support for <code>assertThat</code>. (bd8efd003)</li> <li>Enhanced <code>IterableSubject.containsAtLeastElementsIn().inOrder()</code> to print an extra line that shows only the expected elements in their actual order. (9da7dd184)</li> <li>Annotated Truth for nullness. (2151add71)</li> </ul> </blockquote> </details> <details> <summary>Commits</summary> <ul> <li>See full diff in <a href="https://github.com/google/truth/commits/v1.1.5">compare view</a></li> </ul> </details> <br /> [![Dependabot compatibility score](https://dependabot-badges.githubapp.com/badges/compatibility_score?dependency-name=com.google.truth:truth&package-manager=maven&previous-version=1.1.3&new-version=1.1.5)](https://docs.github.com/en/github/managing-security-vulnerabilities/about-dependabot-security-updates#about-compatibility-scores) Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting `@dependabot rebase`. [//]: # (dependabot-automerge-start) [//]: # (dependabot-automerge-end) --- <details> <summary>Dependabot commands and options</summary> <br /> You can trigger Dependabot actions by commenting on this PR: - `@dependabot rebase` will rebase this PR - `@dependabot recreate` will recreate this PR, overwriting any edits that have been made to it - `@dependabot merge` will merge this PR after your CI passes on it - `@dependabot squash and merge` will squash and merge this PR after your CI passes on it - `@dependabot cancel merge` will cancel a previously requested merge and block automerging - `@dependabot reopen` will reopen this PR if it is closed - `@dependabot close` will close this PR and stop Dependabot recreating it. You can achieve the same result by closing it manually - `@dependabot show <dependency name> ignore conditions` will show all of the ignore conditions of the specified dependency - `@dependabot ignore this major version` will close this PR and stop Dependabot creating any more for this major version (unless you reopen the PR or upgrade to it yourself) - `@dependabot ignore this minor version` will close this PR and stop Dependabot creating any more for this minor version (unless you reopen the PR or upgrade to it yourself) - `@dependabot ignore this dependency` will close this PR and stop Dependabot creating any more for this dependency (unless you reopen the PR or upgrade to it yourself) </details> Fixes #1585 COPYBARA_INTEGRATE_REVIEW=https://github.com/google/auto/pull/1585 from google:dependabot/maven/service/com.google.truth-truth-1.1.5 317bd5762bbb9319f00776df5355a00c7c8af214 PiperOrigin-RevId: 563228642
-rw-r--r--service/pom.xml2
1 files changed, 1 insertions, 1 deletions
diff --git a/service/pom.xml b/service/pom.xml
index fc57b590..a6e0d071 100644
--- a/service/pom.xml
+++ b/service/pom.xml
@@ -38,7 +38,7 @@
<project.build.sourceEncoding>UTF-8</project.build.sourceEncoding>
<java.version>1.8</java.version>
<guava.version>32.1.2-jre</guava.version>
- <truth.version>1.1.3</truth.version>
+ <truth.version>1.1.5</truth.version>
</properties>
<scm>