Skip to content

bump xmlunit-assertj3's AssertJ dependency to 3.27.6#320

Merged
bodewig merged 2 commits into
mainfrom
bump-assertj
Jan 27, 2026
Merged

bump xmlunit-assertj3's AssertJ dependency to 3.27.6#320
bodewig merged 2 commits into
mainfrom
bump-assertj

Conversation

@bodewig
Copy link
Copy Markdown
Member

@bodewig bodewig commented Jan 27, 2026

This is to make people aware of
GHSA-rqfh-9r24-8c9r

XMLUnit itself does not use the affected code in AssertJ so the upgrade is not strictly necessary - and this is why the xmlunit-assertj module is not updated. In fact the assertions provided by xmlunit-assertj3 are the recommended upgrade path for users of AssertJ 4.x.

This is to make people aware of
GHSA-rqfh-9r24-8c9r

XMLUnit itself does not use the affected code in AssertJ so the upgrade
is not strictly necessary - and this is why the xmlunit-assertj module
is not updated. In fact the assertions provided by xmlunit-assertj3 are
the recommended upgrade path for users of AssertJ 4.x.
@bodewig bodewig merged commit 05f2da4 into main Jan 27, 2026
1 check was pending
@bodewig bodewig deleted the bump-assertj branch January 27, 2026 06:25
@coveralls
Copy link
Copy Markdown

coveralls commented Jan 27, 2026

Coverage Status

coverage: 91.781%. remained the same
when pulling 60c8f44 on bump-assertj
into a64d2d1 on main.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants