dependabot[bot] opened a new pull request, #3447:
URL: https://github.com/apache/cxf/pull/3447

   Bumps 
[org.atmosphere:atmosphere-runtime](https://github.com/Atmosphere/atmosphere) 
from 3.1.0 to 4.0.70.
   <details>
   <summary>Release notes</summary>
   <p><em>Sourced from <a 
href="https://github.com/Atmosphere/atmosphere/releases";>org.atmosphere:atmosphere-runtime's
 releases</a>.</em></p>
   <blockquote>
   <h2>Atmosphere 4.0.70</h2>
   <h3>Fixed</h3>
   <ul>
   <li>keep the personal-assistant transport open while keying memory on the 
token</li>
   <li>stop compose hanging without a TTY and warn on an inherited 
LLM_BASE_URL</li>
   <li>resolve the run owner from the AuthInterceptor principal</li>
   <li>key personal-assistant memory on the authenticated principal</li>
   <li>track Boot 3.5.15's Tomcat 10.1.55 in the spring-boot3 profile pin</li>
   <li>close 72 of the 74 open Dependabot alerts across nine packages</li>
   </ul>
   <h3>Changed</h3>
   <ul>
   <li>pin the parity trail in save order, not as a sorted multiset</li>
   <li>log the blog-audit drift entries</li>
   <li>cite the shipping rate limits in the OWASP A09 evidence</li>
   <li>move to Jetty 12.1.12 and port HTTP/3 to the relocated QUIC API</li>
   <li>type-check the Console on TypeScript 7 and make .d.cts reachable</li>
   <li>move atmosphere.js and the e2e suite to TypeScript 7</li>
   <li>take the sample-frontend group bumps, holding TypeScript at 6</li>
   <li>cite Quarkus 3.36.3's real netty baseline in the five BOM pins</li>
   </ul>
   <h2>Atmosphere 4.0.69</h2>
   <h3>Added</h3>
   <ul>
   <li>add the classic-rooms template and gate the two template maps in 
lockstep</li>
   <li>add spring-boot-low-level-handlers, the layer under <a 
href="https://github.com/ManagedService";><code>@​ManagedService</code></a></li>
   <li>add spring-boot-team-rooms, a classic-annotation multi-room chat</li>
   </ul>
   <h3>Fixed</h3>
   <ul>
   <li>stop the personal assistant overwriting an upstream-resolved 
ai.userId</li>
   <li>skip cross-session recall when the resolved runtime is the demo 
fallback</li>
   <li>reattach two Javadoc comments orphaned by the owner-reclaim insert</li>
   <li>stop the CHANGELOG generator crediting reverted commits</li>
   <li>keep the run owner across a recycled request so fact extraction still 
runs</li>
   <li>make the classic-annotation samples work at runtime, not just in 
tests</li>
   <li>resolve templated endpoint paths on WebTransport, not just 
requestURI</li>
   <li>fail a fixture boot as soon as the process dies, not after the 
timeout</li>
   <li>fail the coverage map on entries for samples that no longer exist</li>
   <li>resolve e2e coverage entries to real specs, projects and CI legs</li>
   <li>resolve <a 
href="https://github.com/PathParam";><code>@​PathParam</code></a> on <a 
href="https://github.com/RoomService";><code>@​RoomService</code></a> and add it 
to the servlet scan</li>
   </ul>
   <h3>Changed</h3>
   <ul>
   <li>require evidence in the four matrix rows that certified without it</li>
   <li>log the offline-maven CI regression and the CDI annotation false 
positive</li>
   <li>register the two classic-annotation samples across every gate and 
doc</li>
   <li>log the fabricated container-ledger blog claim and the relayed RAG 
negative grep</li>
   </ul>
   <!-- raw HTML omitted -->
   </blockquote>
   <p>... (truncated)</p>
   </details>
   <details>
   <summary>Changelog</summary>
   <p><em>Sourced from <a 
href="https://github.com/Atmosphere/atmosphere/blob/main/CHANGELOG.md";>org.atmosphere:atmosphere-runtime's
 changelog</a>.</em></p>
   <blockquote>
   <h2>[4.0.70] - 2026-09-01</h2>
   <h3>Fixed</h3>
   <ul>
   <li>keep the personal-assistant transport open while keying memory on the 
token</li>
   <li>stop compose hanging without a TTY and warn on an inherited 
LLM_BASE_URL</li>
   <li>resolve the run owner from the AuthInterceptor principal</li>
   <li>key personal-assistant memory on the authenticated principal</li>
   <li>track Boot 3.5.15's Tomcat 10.1.55 in the spring-boot3 profile pin</li>
   <li>close 72 of the 74 open Dependabot alerts across nine packages</li>
   </ul>
   <h3>Changed</h3>
   <ul>
   <li>pin the parity trail in save order, not as a sorted multiset</li>
   <li>log the blog-audit drift entries</li>
   <li>cite the shipping rate limits in the OWASP A09 evidence</li>
   <li>move to Jetty 12.1.12 and port HTTP/3 to the relocated QUIC API</li>
   <li>type-check the Console on TypeScript 7 and make .d.cts reachable</li>
   <li>move atmosphere.js and the e2e suite to TypeScript 7</li>
   <li>take the sample-frontend group bumps, holding TypeScript at 6</li>
   <li>cite Quarkus 3.36.3's real netty baseline in the five BOM pins</li>
   </ul>
   <h2>[4.0.69] - 2026-08-30</h2>
   <h3>Added</h3>
   <ul>
   <li>add the classic-rooms template and gate the two template maps in 
lockstep</li>
   <li>add spring-boot-low-level-handlers, the layer under <a 
href="https://github.com/ManagedService";><code>@​ManagedService</code></a></li>
   <li>add spring-boot-team-rooms, a classic-annotation multi-room chat</li>
   </ul>
   <h3>Fixed</h3>
   <ul>
   <li>stop the personal assistant overwriting an upstream-resolved 
ai.userId</li>
   <li>skip cross-session recall when the resolved runtime is the demo 
fallback</li>
   <li>reattach two Javadoc comments orphaned by the owner-reclaim insert</li>
   <li>stop the CHANGELOG generator crediting reverted commits</li>
   <li>keep the run owner across a recycled request so fact extraction still 
runs</li>
   <li>make the classic-annotation samples work at runtime, not just in 
tests</li>
   <li>resolve templated endpoint paths on WebTransport, not just 
requestURI</li>
   <li>fail a fixture boot as soon as the process dies, not after the 
timeout</li>
   <li>fail the coverage map on entries for samples that no longer exist</li>
   <li>resolve e2e coverage entries to real specs, projects and CI legs</li>
   <li>resolve <a 
href="https://github.com/PathParam";><code>@​PathParam</code></a> on <a 
href="https://github.com/RoomService";><code>@​RoomService</code></a> and add it 
to the servlet scan</li>
   </ul>
   <h3>Changed</h3>
   <ul>
   <li>require evidence in the four matrix rows that certified without it</li>
   <li>log the offline-maven CI regression and the CDI annotation false 
positive</li>
   <li>register the two classic-annotation samples across every gate and 
doc</li>
   <li>log the fabricated container-ledger blog claim and the relayed RAG 
negative grep</li>
   </ul>
   <!-- raw HTML omitted -->
   </blockquote>
   <p>... (truncated)</p>
   </details>
   <details>
   <summary>Commits</summary>
   <ul>
   <li><a 
href="https://github.com/Atmosphere/atmosphere/commit/796020e0ca3289b9ff2fd26af904e79ac6db987c";><code>796020e</code></a>
 release: Atmosphere 4.0.70</li>
   <li><a 
href="https://github.com/Atmosphere/atmosphere/commit/6e9d23e63f2e613cf4a9fd77cf71930ae0aa1712";><code>6e9d23e</code></a>
 test(checkpoint-temporal): pin the parity trail in save order, not as a 
sorte...</li>
   <li><a 
href="https://github.com/Atmosphere/atmosphere/commit/219136b487e29a59bcd3ce6335456b849f1effb1";><code>219136b</code></a>
 fix(samples): keep the personal-assistant transport open while keying memory 
...</li>
   <li><a 
href="https://github.com/Atmosphere/atmosphere/commit/04488b2515b28fca0e5839bfc6ec13979f9049f6";><code>04488b2</code></a>
 docs(harness): log the blog-audit drift entries</li>
   <li><a 
href="https://github.com/Atmosphere/atmosphere/commit/9862e7d00f0ffbc90aae1353068e82ab9b6f1e92";><code>9862e7d</code></a>
 docs(security): cite the shipping rate limits in the OWASP A09 evidence</li>
   <li><a 
href="https://github.com/Atmosphere/atmosphere/commit/e11ade988e030db5a418e0ba4ee83f491f0bbbe4";><code>e11ade9</code></a>
 fix(cli): stop compose hanging without a TTY and warn on an inherited 
LLM_BAS...</li>
   <li><a 
href="https://github.com/Atmosphere/atmosphere/commit/53e4b9f2ce9450862946b0876074f33ac5477139";><code>53e4b9f</code></a>
 fix(ai): resolve the run owner from the AuthInterceptor principal</li>
   <li><a 
href="https://github.com/Atmosphere/atmosphere/commit/528ec984233449fbd52a7c0abc2058f17f989a57";><code>528ec98</code></a>
 fix(samples): key personal-assistant memory on the authenticated principal</li>
   <li><a 
href="https://github.com/Atmosphere/atmosphere/commit/c80dbc7a0b8f0d747e0f17d5fb39156d3f11057e";><code>c80dbc7</code></a>
 build(deps): move to Jetty 12.1.12 and port HTTP/3 to the relocated QUIC 
API</li>
   <li><a 
href="https://github.com/Atmosphere/atmosphere/commit/da0def8a9b3cea83ceec01c627404c35cc6335dc";><code>da0def8</code></a>
 build(js): type-check the Console on TypeScript 7 and make .d.cts 
reachable</li>
   <li>Additional commits viewable in <a 
href="https://github.com/Atmosphere/atmosphere/compare/atmosphere-project-3.1.0...atmosphere-4.0.70";>compare
 view</a></li>
   </ul>
   </details>
   <br />
   
   
   [![Dependabot compatibility 
score](https://dependabot-badges.githubapp.com/badges/compatibility_score?dependency-name=org.atmosphere:atmosphere-runtime&package-manager=maven&previous-version=3.1.0&new-version=4.0.70)](https://docs.github.com/en/github/managing-security-vulnerabilities/about-dependabot-security-updates#about-compatibility-scores)
   
   Dependabot will resolve any conflicts with this PR as long as you don't 
alter it yourself. You can also trigger a rebase manually by commenting 
`@dependabot rebase`.
   
   [//]: # (dependabot-automerge-start)
   [//]: # (dependabot-automerge-end)
   
   ---
   
   <details>
   <summary>Dependabot commands and options</summary>
   <br />
   
   You can trigger Dependabot actions by commenting on this PR:
   - `@dependabot rebase` will rebase this PR
   - `@dependabot recreate` will recreate this PR, overwriting any edits that 
have been made to it
   - `@dependabot show <dependency name> ignore conditions` will show all of 
the ignore conditions of the specified dependency
   - `@dependabot ignore this major version` will close this PR and stop 
Dependabot creating any more for this major version (unless you reopen the PR 
or upgrade to it yourself)
   - `@dependabot ignore this minor version` will close this PR and stop 
Dependabot creating any more for this minor version (unless you reopen the PR 
or upgrade to it yourself)
   - `@dependabot ignore this dependency` will close this PR and stop 
Dependabot creating any more for this dependency (unless you reopen the PR or 
upgrade to it yourself)
   
   
   </details>


-- 
This is an automated message from the Apache Git Service.
To respond to the message, please log on to GitHub and use the
URL above to go to the specific comment.

To unsubscribe, e-mail: [email protected]

For queries about this service, please contact Infrastructure at:
[email protected]

Reply via email to