This issue lists Renovate updates and detected dependencies. Read the Dependency Dashboard docs to learn more.View this repository on the Mend.io Web Portal .
Rate-Limited
The following updates are currently rate-limited. To force their creation now, click on a checkbox below.
Update ccd-case-document-am-api Docker tag to v1.7.18
Update dependency microsoft/ApplicationInsights-Java to v3.7.8
Update dependency org.apache.pdfbox:pdfbox to v3.0.7
Update dependency org.projectlombok:lombok to v1.18.46
Update dependency org.springdoc:springdoc-openapi-starter-webmvc-ui to v2.8.17
Update dependency org.springframework.data:spring-data-commons to v3.5.11
Update em-ccdorc Docker tag to v2.1.2
Update em-stitching Docker tag to v1.1.4
Update log4j2 monorepo to v2.25.4 (org.apache.logging.log4j:log4j-to-slf4j, org.apache.logging.log4j:log4j-api)
Update Node.js to v22.22.2
Update plugin com.github.hmcts.rse-cft-lib to v0.19.2098
Update spring cloud (org.springframework.cloud:spring-cloud-starter-contract-stub-runner, org.springframework.cloud:spring-cloud-starter-openfeign, org.springframework.cloud:spring-cloud-starter-bootstrap)
Update spring security to v6.5.10 (org.springframework.security:spring-security-web, org.springframework.security:spring-security-test, org.springframework.security:spring-security-taglibs, org.springframework.security:spring-security-saml2-service-provider, org.springframework.security:spring-security-rsocket, org.springframework.security:spring-security-oauth2-resource-server, org.springframework.security:spring-security-oauth2-jose, org.springframework.security:spring-security-oauth2-core, org.springframework.security:spring-security-oauth2-client, org.springframework.security:spring-security-messaging, org.springframework.security:spring-security-ldap, org.springframework.security:spring-security-data, org.springframework.security:spring-security-crypto, org.springframework.security:spring-security-config, org.springframework.security:spring-security-cas, org.springframework.security:spring-security-aspects, org.springframework.security:spring-security-acl, org.springframework.security:spring-security-core)
Update dependency au.com.dius.pact.consumer:junit5 to v4.7.0
Update dependency com.google.guava:guava to v33.6.0-jre
Update dependency com.launchdarkly:launchdarkly-java-server-sdk to v7.13.2
Update dependency com.microsoft.playwright:playwright to v1.59.0
Update dependency org.bouncycastle:bcpkix-jdk18on to v1.84
Update idam-pr Docker tag to v2.4.0
Update plugin au.com.dius.pact to v4.7.0
Update plugin com.github.ben-manes.versions to v0.54.0
Update plugin org.owasp.dependencycheck to v12.2.1
Update actions/checkout action to v6
Update GitHub Artifact Actions (major) (actions/download-artifact, actions/upload-artifact)
Update Node.js to v24
Update plugin org.sonarqube to v7
Update plugin org.springframework.boot to v4
Update spring cloud to v5 (major) (org.springframework.cloud:spring-cloud-starter-contract-stub-runner, org.springframework.cloud:spring-cloud-starter-openfeign, org.springframework.cloud:spring-cloud-starter-bootstrap)
Update spring security to v7 (major) (org.springframework.security:spring-security-web, org.springframework.security:spring-security-test, org.springframework.security:spring-security-taglibs, org.springframework.security:spring-security-saml2-service-provider, org.springframework.security:spring-security-rsocket, org.springframework.security:spring-security-oauth2-resource-server, org.springframework.security:spring-security-oauth2-jose, org.springframework.security:spring-security-oauth2-core, org.springframework.security:spring-security-oauth2-client, org.springframework.security:spring-security-messaging, org.springframework.security:spring-security-ldap, org.springframework.security:spring-security-data, org.springframework.security:spring-security-crypto, org.springframework.security:spring-security-config, org.springframework.security:spring-security-cas, org.springframework.security:spring-security-aspects, org.springframework.security:spring-security-acl, org.springframework.security:spring-security-core)
🔐 Create all rate-limited PRs at once 🔐
Open
The following updates have all been created. To force a retry/rebase of any, click on a checkbox below.
PR Closed (Blocked)
The following updates are blocked by an existing closed PR. To recreate the PR, click on a checkbox below.
Detected Dependencies
docker-compose (1)
docker-compose.yml
dockerfile (1)
Dockerfile (1)
hmctsprod.azurecr.io/base/java 21-distroless
github-actions (2)
.github/workflows/ccd-diff.yml (8)
actions/setup-java v5
actions/checkout v5 → [Updates: v6]
actions/upload-artifact v5 → [Updates: v7]
actions/setup-node v6
actions/download-artifact v6 → [Updates: v8]
actions/download-artifact v6 → [Updates: v8]
actions/upload-artifact v5 → [Updates: v7]
node 24
.github/workflows/ci.yml (2)
actions/checkout v6
actions/setup-java v5
gradle (2)
build.gradle (92)
cz.habarta.typescript-generator:typescript-generator-gradle-plugin 3.2.1263
org.owasp.dependencycheck 12.1.3 → [Updates: 12.2.1]
org.sonarqube 6.3.1.5724 → [Updates: 7.2.3.7755]
io.spring.dependency-management 1.1.7
org.springframework.boot 3.5.10 → [Updates: 3.5.13, 4.0.5]
com.github.ben-manes.versions 0.50.0 → [Updates: 0.54.0]
hmcts.ccd.sdk 6.7.2
au.com.dius.pact 4.3.10 → [Updates: 4.7.0]
com.github.hmcts.rse-cft-lib 0.19.2017 → [Updates: 0.19.2098]
checkstyle 9.3 → [Updates: 13.4.0]
pmd 7.21.0 → [Updates: 7.23.0]
com.google.guava:guava 33.4.8-jre → [Updates: 33.6.0-jre]
org.springframework.security:spring-security-core 6.5.8 → [Updates: 6.5.10, 7.0.5]
org.springframework.security:spring-security-acl 6.5.8 → [Updates: 6.5.10, 7.0.5]
org.springframework.security:spring-security-aspects 6.5.8 → [Updates: 6.5.10, 7.0.5]
org.springframework.security:spring-security-cas 6.5.8 → [Updates: 6.5.10, 7.0.5]
org.springframework.security:spring-security-config 6.5.8 → [Updates: 6.5.10, 7.0.5]
org.springframework.security:spring-security-crypto 6.5.8 → [Updates: 6.5.10, 7.0.5]
org.springframework.security:spring-security-data 6.5.8 → [Updates: 6.5.10, 7.0.5]
org.springframework.security:spring-security-ldap 6.5.8 → [Updates: 6.5.10, 7.0.5]
org.springframework.security:spring-security-messaging 6.5.8 → [Updates: 6.5.10, 7.0.5]
org.springframework.security:spring-security-oauth2-client 6.5.8 → [Updates: 6.5.10, 7.0.5]
org.springframework.security:spring-security-oauth2-core 6.5.8 → [Updates: 6.5.10, 7.0.5]
org.springframework.security:spring-security-oauth2-jose 6.5.8 → [Updates: 6.5.10, 7.0.5]
org.springframework.security:spring-security-oauth2-resource-server 6.5.8 → [Updates: 6.5.10, 7.0.5]
org.springframework.security:spring-security-openid 6.5.8
org.springframework.security:spring-security-remoting 6.5.8
org.springframework.security:spring-security-rsocket 6.5.8 → [Updates: 6.5.10, 7.0.5]
org.springframework.security:spring-security-saml2-service-provider 6.5.8 → [Updates: 6.5.10, 7.0.5]
org.springframework.security:spring-security-taglibs 6.5.8 → [Updates: 6.5.10, 7.0.5]
org.springframework.security:spring-security-test 6.5.8 → [Updates: 6.5.10, 7.0.5]
org.springframework.security:spring-security-web 6.5.8 → [Updates: 6.5.10, 7.0.5]
org.springframework.security:spring-security-rsa 1.1.5
org.bouncycastle:bcpkix-jdk18on 1.83 → [Updates: 1.84]
org.camunda.connect:camunda-connect-connectors-all 7.24.0
commons-fileupload:commons-fileupload 1.6.0
com.fasterxml.jackson.core:jackson-databind 2.16.0 → [Updates: 2.21.2]
com.fasterxml.jackson.core:jackson-core 2.16.0 → [Updates: 2.21.2]
com.fasterxml.jackson.core:jackson-annotations 2.16.0 → [Updates: 2.21]
com.github.hmcts:befta-fw 9.2.4
io.swagger:swagger-annotations 1.6.16
ch.qos.logback:logback-classic 1.5.32
ch.qos.logback:logback-core 1.5.32
com.github.hmcts:core-case-data-store-client 5.2.0
com.github.hmcts:ccd-case-document-am-client 1.59.2
com.github.hmcts:idam-java-client 3.0.5
com.github.hmcts:pdf-service-client 8.0.2
com.github.hmcts.java-logging:logging 8.0.0
com.github.hmcts:service-auth-provider-java-client 5.3.3
net.logstash.logback:logstash-logback-encoder 9.0
org.apache.logging.log4j:log4j-api 2.25.3 → [Updates: 2.25.4]
org.apache.logging.log4j:log4j-to-slf4j 2.25.3 → [Updates: 2.25.4]
org.elasticsearch:elasticsearch 7.17.29 → [Updates: 9.3.3]
org.projectlombok:lombok 1.18.42 → [Updates: 1.18.46]
org.springdoc:springdoc-openapi-starter-webmvc-ui 2.8.16 → [Updates: 2.8.17, 3.0.3]
org.springframework.retry:spring-retry 2.0.12
org.springframework.cloud:spring-cloud-starter-netflix-hystrix 2.2.10.RELEASE
org.springframework.cloud:spring-cloud-starter-bootstrap 4.3.1 → [Updates: 4.3.2, 5.0.1]
org.springframework.cloud:spring-cloud-starter-openfeign 4.3.1 → [Updates: 4.3.2, 5.0.1]
org.springframework.data:spring-data-commons 3.5.9 → [Updates: 3.5.11, 4.0.5]
uk.gov.service.notify:notifications-java-client 6.0.0-RELEASE
com.launchdarkly:launchdarkly-java-server-sdk 7.12.0 → [Updates: 7.13.2]
org.apache.commons:commons-collections4 4.5.0
org.apache.commons:commons-lang3 3.20.0
com.github.ben-manes.caffeine:caffeine 3.2.3
org.camunda.bpm:camunda-external-task-client 7.24.0
org.postgresql:postgresql 42.7.10
org.flywaydb:flyway-database-postgresql 11.20.3 → [Updates: 12.4.0]
org.flywaydb:flyway-core 11.20.3 → [Updates: 12.4.0]
com.github.hmcts:fortify-client 1.4.10
jakarta.enterprise:jakarta.enterprise.cdi-api 4.1.0
com.jayway.awaitility:awaitility 1.7.0
com.github.stefanbirkner:system-lambda 1.2.1
org.assertj:assertj-core 3.27.7
org.assertj:assertj-guava 3.27.7
org.springframework.cloud:spring-cloud-starter-contract-stub-runner 4.3.1 → [Updates: 4.3.3, 5.0.2]
org.mockito:mockito-inline 5.2.0
io.github.openfeign:feign-jackson 13.8 → [Updates: 13.12]
org.apache.pdfbox:pdfbox 3.0.6 → [Updates: 3.0.7]
com.microsoft.playwright:playwright 1.58.0 → [Updates: 1.59.0]
org.camunda.bpm.dmn:camunda-engine-dmn 7.24.0
org.camunda.bpm:camunda-engine-plugin-spin 7.24.0
org.camunda.bpm.assert:camunda-bpm-assert 15.0.0
org.camunda.bpm:camunda-engine 7.24.0
org.testcontainers:junit-jupiter 1.21.4
org.testcontainers:postgresql 1.21.4
com.github.hmcts:document-management-client 7.0.1
com.github.hmcts:service-auth-provider-java-client 5.3.3
au.com.dius.pact.consumer:junit5 4.6.20 → [Updates: 4.7.0]
com.microsoft.playwright:playwright 1.58.0 → [Updates: 1.59.0]
org.junit-pioneer:junit-pioneer 2.3.0
io.github.artsok:rerunner-jupiter 2.1.6
settings.gradle
gradle-wrapper (1)
gradle/wrapper/gradle-wrapper.properties (1)
gradle 8.14.4 → [Updates: 9.4.1]
helm-values (1)
charts/sptribs-case-api/values.yaml
helmv3 (1)
charts/sptribs-case-api/Chart.yaml (6)
java 5.3.0
ccd 9.2.2
idam-pr 2.3.1 → [Updates: 2.4.0]
ccd-case-document-am-api 1.7.14 → [Updates: 1.7.18]
em-ccdorc 2.1.0 → [Updates: 2.1.2]
em-stitching 1.1.0 → [Updates: 1.1.4]
npm (2)
bin/data-loss/package.json (3)
pg ^8.16.0 → [Updates: ^8.16.0]
pgpass ^1.0.5
jsondiffpatch ^0.7.3
package.json (1)
nvm (1)
.nvmrc (1)
node 22.22.0 → [Updates: 22.22.2, 24.15.0]
regex (1)
Dockerfile (1)
microsoft/ApplicationInsights-Java 3.7.7 → [Updates: 3.7.8]
renovate-config-presets (1)
.github/renovate.json
This issue lists Renovate updates and detected dependencies. Read the Dependency Dashboard docs to learn more.
View this repository on the Mend.io Web Portal.
Rate-Limited
The following updates are currently rate-limited. To force their creation now, click on a checkbox below.
org.apache.logging.log4j:log4j-to-slf4j,org.apache.logging.log4j:log4j-api)org.springframework.cloud:spring-cloud-starter-contract-stub-runner,org.springframework.cloud:spring-cloud-starter-openfeign,org.springframework.cloud:spring-cloud-starter-bootstrap)org.springframework.security:spring-security-web,org.springframework.security:spring-security-test,org.springframework.security:spring-security-taglibs,org.springframework.security:spring-security-saml2-service-provider,org.springframework.security:spring-security-rsocket,org.springframework.security:spring-security-oauth2-resource-server,org.springframework.security:spring-security-oauth2-jose,org.springframework.security:spring-security-oauth2-core,org.springframework.security:spring-security-oauth2-client,org.springframework.security:spring-security-messaging,org.springframework.security:spring-security-ldap,org.springframework.security:spring-security-data,org.springframework.security:spring-security-crypto,org.springframework.security:spring-security-config,org.springframework.security:spring-security-cas,org.springframework.security:spring-security-aspects,org.springframework.security:spring-security-acl,org.springframework.security:spring-security-core)actions/download-artifact,actions/upload-artifact)org.springframework.cloud:spring-cloud-starter-contract-stub-runner,org.springframework.cloud:spring-cloud-starter-openfeign,org.springframework.cloud:spring-cloud-starter-bootstrap)org.springframework.security:spring-security-web,org.springframework.security:spring-security-test,org.springframework.security:spring-security-taglibs,org.springframework.security:spring-security-saml2-service-provider,org.springframework.security:spring-security-rsocket,org.springframework.security:spring-security-oauth2-resource-server,org.springframework.security:spring-security-oauth2-jose,org.springframework.security:spring-security-oauth2-core,org.springframework.security:spring-security-oauth2-client,org.springframework.security:spring-security-messaging,org.springframework.security:spring-security-ldap,org.springframework.security:spring-security-data,org.springframework.security:spring-security-crypto,org.springframework.security:spring-security-config,org.springframework.security:spring-security-cas,org.springframework.security:spring-security-aspects,org.springframework.security:spring-security-acl,org.springframework.security:spring-security-core)Open
The following updates have all been created. To force a retry/rebase of any, click on a checkbox below.
com.fasterxml.jackson.core:jackson-annotations,com.fasterxml.jackson.core:jackson-core,com.fasterxml.jackson.core:jackson-databind)org.flywaydb:flyway-core,org.flywaydb:flyway-database-postgresql)PR Closed (Blocked)
The following updates are blocked by an existing closed PR. To recreate the PR, click on a checkbox below.
Detected Dependencies
docker-compose (1)
dockerfile (1)
github-actions (2)
gradle (2)
gradle-wrapper (1)
helm-values (1)
helmv3 (1)
npm (2)
nvm (1)
regex (1)
renovate-config-presets (1)