Skip to content

Chore(deps): Bump org.slf4j:slf4j-bom from 2.0.18 to 2.0.20 - #2325

Open
dependabot[bot] wants to merge 1 commit into
mainfrom
dependabot/maven/main/org.slf4j-slf4j-bom-2.0.20
Open

dependabot[bot] wants to merge 1 commit into
mainfrom
dependabot/maven/main/org.slf4j-slf4j-bom-2.0.20

Conversation

@dependabot

@dependabot dependabot Bot commented on behalf of github Oct 1, 2026

Copy link
Copy Markdown
Contributor

Bumps org.slf4j:slf4j-bom from 2.0.18 to 2.0.20.

Release notes

Sourced from org.slf4j:slf4j-bom's releases.

SLF4J 2.0.20

2026-09-22 - Release of SLF4J 2.0.20

• Marker instances are slated to become immutable in future releases. As such, methods in the Marker interface adding/removing children are now marked as deprecated.

• A bit-wise identical binary of this version can be reproduced by building from source code at commit 58d80a4fe8f2e811707fcfba4d292b5d62fc2fe9 associated with the tag v_2.0.20. Release built using Java "21" 2023-10-17 LTS build 21.0.1.+12-LTS-29 under Linux Debian 11.6.

Full Changelog: qos-ch/slf4j@v_2.0.19...v_2.0.20

SLF4J 2.0.19

2026-09-04 - Release of SLF4J 2.0.19

  • When the fluent API was used with XLogger/LoggerWrapper in the slf4j-ext module, caller location was incorrectly reported. To correct this, LoggerWrapper now delegates makeLoggingEventBuilder() to the wrapped logger so that the application caller can be correctly extracted. This issue was reported in issues/464.

  • In slf4j-api/DefaultLoggingEventBuilder, a failing toString() invocation on a key-value value, including StackOverflowError, no longer aborts logging. The builder now substitutes [FAILED toString()], matching the existing behaviour of MessageFormatter for message arguments. This issue was reported in issues/448.

  • The isLoggable() method in SLF4JPlatformLogger now maps System.Logger.Level.ALL and Level.OFF the same way as log(), that is ALL as TRACE and OFF as ERROR, instead of treating both as always loggable. This is a follow-up to the changes introduced in 2.0.17. See issues/430.

  • Published JAR files now package each module's own LICENSE.txt under META-INF/. Previously the parent POM copied the repository-root MIT license into every module, so Apache-2.0 modules such as jcl-over-slf4j and log4j-over-slf4j shipped the wrong license text. This issue was reported in issues/465.

  • A bit-wise identical binary of this version can be reproduced by building from source code at commit f0fc3e52a16d5053039495f4f3b64d191508204f associated with the tag v_2.0.19. Release built using Java "21" 2023-10-17 LTS build 21.0.1.+12-LTS-29 under Linux Debian 11.6.

Commits
  • 58d80a4 prepare release 2.0.20
  • ef47ab9 deprecate methods for adding/remocing children to markers
  • 6b6c63e fix failing test on Windows
  • 233d4d1 renamed LoggerTestSuite.java as SimpleLoggerAcceptanceTest
  • bf3a7b9 start work on 2.0.20-SNAPSHOT
  • f0fc3e5 prepare release 2.0.19
  • 2288d0c fix issues/464. slf4j-ext/XLogger incorrect caller extraction when the fluent...
  • 6ff7f77 test: pin fluent API caller method name
  • 2b3f94b SLF4JPlatformLogger.isLoggable should handle Logger.ALL and Logger.OFF in a c...
  • 9221f77 fix(api): guard addKeyValue value toString from fatal errors
  • Additional commits viewable in compare view

Dependabot compatibility score

You can trigger a rebase of this PR by commenting @dependabot rebase.


Dependabot commands and options

You can trigger Dependabot actions by commenting on this PR:

  • @dependabot rebase will rebase this PR
  • @dependabot recreate will recreate this PR, overwriting any edits that have been made to it
  • @dependabot show <dependency name> ignore conditions will show all of the ignore conditions of the specified dependency
  • @dependabot ignore this major version will close this PR and stop Dependabot creating any more for this major version (unless you reopen the PR or upgrade to it yourself)
  • @dependabot ignore this minor version will close this PR and stop Dependabot creating any more for this minor version (unless you reopen the PR or upgrade to it yourself)
  • @dependabot ignore this dependency will close this PR and stop Dependabot creating any more for this dependency (unless you reopen the PR or upgrade to it yourself)

Bumps [org.slf4j:slf4j-bom](https://github.com/qos-ch/slf4j) from 2.0.18 to 2.0.20.
- [Release notes](https://github.com/qos-ch/slf4j/releases)
- [Commits](qos-ch/slf4j@v_2.0.18...v_2.0.20)

---
updated-dependencies:
- dependency-name: org.slf4j:slf4j-bom
  dependency-version: 2.0.20
  dependency-type: direct:production
  update-type: version-update:semver-patch
...

Signed-off-by: dependabot[bot] <support@github.com>
@dependabot dependabot Bot added dependencies Pull requests that update a dependency file java Pull requests that update Java code labels Oct 1, 2026
@codecov

codecov Bot commented Oct 1, 2026

Copy link
Copy Markdown

Codecov Report

✅ All modified and coverable lines are covered by tests.
✅ Project coverage is 85.41%. Comparing base (f351e37) to head (7aef0cd).

Additional details and impacted files
@@            Coverage Diff            @@
##               main    #2325   +/-   ##
=========================================
  Coverage     85.41%   85.41%           
  Complexity     2568     2568           
=========================================
  Files           242      242           
  Lines          7577     7577           
  Branches        399      399           
=========================================
  Hits           6472     6472           
  Misses          869      869           
  Partials        236      236           

☔ View full report in Codecov by Harness.
📢 Have feedback on the report? Share it here.

🚀 New features to boost your workflow:
  • ❄️ Test Analytics: Detect flaky tests, report on failures, and find test suite problems.

This branch has not been deployed

No deployments
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

dependencies Pull requests that update a dependency file java Pull requests that update Java code

Projects

None yet

Development

Successfully merging this pull request may close these issues.

0 participants