solrbot opened a new pull request, #4980:
URL: https://github.com/apache/solr/pull/4980

   This PR contains the following updates:
   
   | Package | Type | Update | Change |
   |---|---|---|---|
   | 
[io.netty:netty-tcnative-classes](https://redirect.github.com/netty/netty-tcnative)
 | dependencies | patch | `2.0.82.Final` → `2.0.84.Final` |
   | 
[io.netty:netty-tcnative-boringssl-static](https://redirect.github.com/netty/netty-tcnative/netty-tcnative-boringssl-static/)
 ([source](https://redirect.github.com/netty/netty-tcnative)) | dependencies | 
patch | `2.0.82.Final` → `2.0.84.Final` |
   | [io.netty:netty-transport-native-epoll](https://netty.io/) 
([source](https://redirect.github.com/netty/netty)) | dependencies | patch | 
`4.2.17.Final` → `4.2.18.Final` |
   | [io.netty:netty-transport-classes-epoll](https://netty.io/) 
([source](https://redirect.github.com/netty/netty)) | dependencies | patch | 
`4.2.17.Final` → `4.2.18.Final` |
   | [io.netty:netty-handler](https://netty.io/) 
([source](https://redirect.github.com/netty/netty)) | dependencies | patch | 
`4.2.17.Final` → `4.2.18.Final` |
   | [io.netty:netty-codec-http](https://netty.io/) 
([source](https://redirect.github.com/netty/netty)) | dependencies | patch | 
`4.2.17.Final` → `4.2.18.Final` |
   | [io.netty:netty-bom](https://netty.io/) 
([source](https://redirect.github.com/netty/netty)) | dependencies | patch | 
`4.2.17.Final` → `4.2.18.Final` |
   | [io.grpc:grpc-util](https://redirect.github.com/grpc/grpc-java) | 
dependencies | minor | `1.83.1` → `1.84.0` |
   | [io.grpc:grpc-stub](https://redirect.github.com/grpc/grpc-java) | 
dependencies | minor | `1.83.1` → `1.84.0` |
   | [io.grpc:grpc-protobuf-lite](https://redirect.github.com/grpc/grpc-java) | 
dependencies | minor | `1.83.1` → `1.84.0` |
   | [io.grpc:grpc-protobuf](https://redirect.github.com/grpc/grpc-java) | 
dependencies | minor | `1.83.1` → `1.84.0` |
   | [io.grpc:grpc-netty](https://redirect.github.com/grpc/grpc-java) | 
dependencies | minor | `1.83.1` → `1.84.0` |
   | [io.grpc:grpc-core](https://redirect.github.com/grpc/grpc-java) | 
dependencies | minor | `1.83.1` → `1.84.0` |
   | [io.grpc:grpc-context](https://redirect.github.com/grpc/grpc-java) | 
dependencies | minor | `1.83.1` → `1.84.0` |
   | [io.grpc:grpc-bom](https://redirect.github.com/grpc/grpc-java) | 
dependencies | minor | `1.83.1` → `1.84.0` |
   | [io.grpc:grpc-api](https://redirect.github.com/grpc/grpc-java) | 
dependencies | minor | `1.83.1` → `1.84.0` |
   | 
[com.google.protobuf:protobuf-java-util](https://developers.google.com/protocol-buffers/)
 ([source](https://redirect.github.com/protocolbuffers/protobuf)) | 
dependencies | patch | `4.36.0` → `4.36.2` |
   | 
[com.google.protobuf:protobuf-java](https://developers.google.com/protocol-buffers/)
 ([source](https://redirect.github.com/protocolbuffers/protobuf)) | 
dependencies | patch | `4.36.0` → `4.36.2` |
   
   ---
   
   ### Release Notes
   
   <details>
   <summary>grpc/grpc-java (io.grpc:grpc-util)</summary>
   
   ### 
[`v1.84.0`](https://redirect.github.com/grpc/grpc-java/releases/tag/v1.84.0)
   
   In this release we drop support for Android API level 23 or lower 
(Marshmallow or earlier), following [Google Play Service’s now requiring a 
minimum of API level 
24](https://support.google.com/googleplay/answer/9037938?hl=en) (Android 7.0 
Nougat).
   
   ##### API Changes
   
   - xds: Supports injecting custom LDS Resource Name Resolvers 
([#&#8203;12925](https://redirect.github.com/grpc/grpc-java/issues/12925)) 
([`ac02c6f`](https://redirect.github.com/grpc/grpc-java/commit/ac02c6f37))
   - xds: Add support for creating `XdsServerBuilder` with `SocketAddress`es 
([#&#8203;12925](https://redirect.github.com/grpc/grpc-java/issues/12925)) 
([`ac02c6f`](https://redirect.github.com/grpc/grpc-java/commit/ac02c6f37))
   - api: Add a Supplier overload to Context 
([#&#8203;12935](https://redirect.github.com/grpc/grpc-java/issues/12935)) 
([`6966536`](https://redirect.github.com/grpc/grpc-java/commit/696653600))
   
   ##### Behavior Changes
   
   - core: update SPIFFE certificate extraction to comply with X509-SVID spec 
([#&#8203;12961](https://redirect.github.com/grpc/grpc-java/issues/12961)) 
([`96807d8`](https://redirect.github.com/grpc/grpc-java/commit/96807d898))\
     Ignore all but the first certificate if the x5c JWK parameter contains 
multiple values.\
     Skip the JWK entry instead of stopping execution or throwing when x5c is 
missing or contains an empty list, complying with the requirement that entries 
without x5c must be ignored.
   
   ##### Bug Fixes
   
   - core: reference-count shared transport factory for OOB channels 
([#&#8203;12985](https://redirect.github.com/grpc/grpc-java/issues/12985)) 
([`72c6e5f`](https://redirect.github.com/grpc/grpc-java/commit/72c6e5f91))\
     Fixes a bug whereby an OOB channel shutdown incorrectly shut down the 
shared transport factory with the main channel, and the main channel was unable 
to create subchannels anymore and faced an exception in doing so.
   - xds: Fix `shutdownNow()` becoming a no-op after `shutdown()` 
([#&#8203;12982](https://redirect.github.com/grpc/grpc-java/issues/12982)) 
([`3cb7007`](https://redirect.github.com/grpc/grpc-java/commit/3cb700719))
   - xds: Add Http11ProxyUpstreamTransport to MessagePrinter 
([#&#8203;12971](https://redirect.github.com/grpc/grpc-java/issues/12971)) 
([`d49a589`](https://redirect.github.com/grpc/grpc-java/commit/d49a589f4))
   - core, xds: Append child channel configurators instead of overwriting 
([#&#8203;12921](https://redirect.github.com/grpc/grpc-java/pull/12921)) 
([`296c007`](https://redirect.github.com/grpc/grpc-java/commit/296c007c1)) 
Chains multiple childChannelConfigurator() calls instead of overwriting them in 
ManagedChannelImplBuilder and XdsServerBuilder, ensuring all configurators are 
preserved and executed when child channels are created.
   - rls: Implement stale\_header\_data caching and propagation in RLS 
([#&#8203;12972](https://redirect.github.com/grpc/grpc-java/pull/12972)) 
([`7843bd4`](https://redirect.github.com/grpc/grpc-java/commit/7843bd437)) 
Caches header\_data received in RouteLookupResponse and sends it back as 
stale\_header\_data in RouteLookupRequest when refreshing stale cache entries, 
complying with the RLS specification.
   
   ##### Improvements
   
   - netty: Fix client-initiated stream limit bypass in NettyServerHandler 
([#&#8203;12933](https://redirect.github.com/grpc/grpc-java/issues/12933)) 
([`56205f9`](https://redirect.github.com/grpc/grpc-java/commit/56205f91c)) 
Configure max active streams limit directly upon `DefaultHttp2Connection` 
initialization. Because `NettyServerHandler` instantiates 
`DefaultHttp2Connection` directly rather than using Netty's 
`AbstractHttp2ConnectionHandlerBuilder`, it missed Netty's built-in 
[CVE-2026-47244](https://redirect.github.com/advisories/GHSA-5x3r-wrvg-rp6q) 
patch. This left a pre-handshake window where the server's local connection 
allowed up to Integer.MAX\_VALUE active client-initiated streams until a 
SETTINGS\_ACK was received. Enforcing the limit proactively at startup closes 
this vulnerability window and prevents client-initiated stream floods / 
resource exhaustion.
   - servlet: `AsyncServletOutputStreamWriter` detect and handle write when not 
ready 
([#&#8203;12732](https://redirect.github.com/grpc/grpc-java/issues/12732)) 
([`46f3080`](https://redirect.github.com/grpc/grpc-java/commit/46f308051)) In 
highly concurrent scenarios, cached servlet container ready to write state can 
become  stale. The servlet container may have already transitioned to a 'not 
ready' state, but the corresponding callback has not yet updated gRPC's 
internal state. This fix makes the ready state to be evaluated explicitly 
before attempting to write directly to the servlet output stream.
   - okhttp: Move connection window update before stream termination logic 
([#&#8203;12990](https://redirect.github.com/grpc/grpc-java/issues/12990)) 
([`0f859c3`](https://redirect.github.com/grpc/grpc-java/commit/0f859c3bb)) By 
RFC 9113, section 6.9, receivers must take frames into account for flow control 
even if they're errored. This change moves the stream error response logic 
after connection window updates
   - core: Coalesce Contiguous Small Buffers for ReadableBuffer to prevent OOM 
([#&#8203;12924](https://redirect.github.com/grpc/grpc-java/issues/12924)) 
([`0585d48`](https://redirect.github.com/grpc/grpc-java/commit/0585d481a))
   - s2a: Default to Post Quantum Cryptography key exchange group 
([#&#8203;12894](https://redirect.github.com/grpc/grpc-java/issues/12894)) 
([`bc01994`](https://redirect.github.com/grpc/grpc-java/commit/bc01994b7))
   - binder: Let servers load their SecurityPolicy asynchronously 
([`9fdef96`](https://redirect.github.com/grpc/grpc-java/commit/9fdef96dc))
   - binder: normalize failed auth future status message 
([`9ffa1e1`](https://redirect.github.com/grpc/grpc-java/commit/9ffa1e1b7))
   
   ##### Dependencies
   
   - compiler: Update maximum supported edition to EDITION\_2026 
([#&#8203;12945](https://redirect.github.com/grpc/grpc-java/issues/12945)) 
([`6ccd065`](https://redirect.github.com/grpc/grpc-java/commit/6ccd0658e)). 
Update the maximum supported edition in the Java gRPC compiler plugin to 
EDITION\_2026 when compiling against Protobuf version 7.35.0 (v35.0) or later.
   - api: Bump Context to JDK 8 
([`5d0a012`](https://redirect.github.com/grpc/grpc-java/commit/5d0a012fa))
   - netty: Upgrade Netty to 4.2.16 and netty-tcnative to 2.0.81 
([#&#8203;12969](https://redirect.github.com/grpc/grpc-java/pull/12969)) 
([`1bc2f5a`](https://redirect.github.com/grpc/grpc-java/commit/1bc2f5a34))
   
   ##### Documentation
   
   - api: Better explain the executors and how to configure them 
([`ee08f53`](https://redirect.github.com/grpc/grpc-java/commit/ee08f5337))
   
   ##### New Features
   
   - core, opentelemetry: Implement LB Delay Observability (Proposal A121) 
([#&#8203;12807](https://redirect.github.com/grpc/grpc-java/pull/12807)) 
([`073fd5e`](https://redirect.github.com/grpc/grpc-java/commit/073fd5ea1)) 
Implements attempt-level RPC delay observability across the core delayed 
transport, built-in load balancers (pick\_first, round\_robin), RLS, and xDS 
policies, aligned with [gRFC 
A121](https://redirect.github.com/grpc/proposal/pull/556). Adds 
LoadBalancer.PickResult.withNoResult(delayType, delayReason) and delay tracing 
callbacks on ClientStreamTracer. Records attempt delay duration metrics 
(grpc.client.attempt.delay.duration) and child tracing spans ("Attempt Delay") 
via the OpenTelemetry plugin.
   
   ##### Thanks to
   
   [@&#8203;Zhengcy05](https://redirect.github.com/Zhengcy05)
   [@&#8203;carl-mastrangelo](https://redirect.github.com/carl-mastrangelo)
   [@&#8203;themechbro](https://redirect.github.com/themechbro)
   [@&#8203;JasonLunn](https://redirect.github.com/JasonLunn)
   [@&#8203;martinbaillie](https://redirect.github.com/martinbaillie)
   [@&#8203;eado](https://redirect.github.com/eado)
   
[@&#8203;TimurRakhmatullin86](https://redirect.github.com/TimurRakhmatullin86)
   
   </details>
   
   ---
   
   ### Configuration
   
   📅 **Schedule**: (UTC)
   
   - Branch creation
     - "before 9am on the first day of the month"
   - Automerge
     - At any time (no schedule defined)
   
   🚦 **Automerge**: Disabled by config. Please merge this manually once you are 
satisfied.
   
   ♻ **Rebasing**: Whenever PR becomes conflicted, or you tick the rebase/retry 
checkbox.
   
   👻 **Immortal**: This PR will be recreated if closed unmerged. Get [config 
help](https://redirect.github.com/renovatebot/renovate/discussions) if that's 
undesired.
   
   ---
   
    - [ ] <!-- rebase-check -->If you want to rebase/retry this PR, check this 
box
   
   ---
   
   This PR has been generated by [Renovate 
Bot](https://redirect.github.com/solrbot/renovate-github-action)
   
<!--renovate-debug:eyJjcmVhdGVkSW5WZXIiOiI0My4xNzAuMTgiLCJ1cGRhdGVkSW5WZXIiOiI0My4xNzAuMTgiLCJ0YXJnZXRCcmFuY2giOiJtYWluIiwibGFiZWxzIjpbImV4ZW1wdC1zdGFsZSJdfQ==-->
   


-- 
This is an automated message from the Apache Git Service.
To respond to the message, please log on to GitHub and use the
URL above to go to the specific comment.

To unsubscribe, e-mail: [email protected]

For queries about this service, please contact Infrastructure at:
[email protected]


---------------------------------------------------------------------
To unsubscribe, e-mail: [email protected]
For additional commands, e-mail: [email protected]

Reply via email to