Skip to content

chore(deps): bump quarkus.version from 3.39.4 to 3.40.0 - #258

Open
dependabot[bot] wants to merge 1 commit into
mainfrom
dependabot/maven/quarkus.version-3.40.0
Open

dependabot[bot] wants to merge 1 commit into
mainfrom
dependabot/maven/quarkus.version-3.40.0

Conversation

@dependabot

@dependabot dependabot Bot commented on behalf of github Oct 1, 2026

Copy link
Copy Markdown
Contributor

Bumps quarkus.version from 3.39.4 to 3.40.0.
Updates io.quarkus:quarkus-bom from 3.39.4 to 3.40.0

Release notes

Sourced from io.quarkus:quarkus-bom's releases.

3.40.0

Complete changelog

  • #56750 - Enhance CycloneDX documentation and configuration options description to stress the priority on JSON format
  • #56829 - [3.40] Update to Scalpel 0.4.2

3.40.0.CR1

Complete changelog

3.39.5

Complete changelog

  • #56037 - Always complete the export when the OTLP sender is shut down
  • #56255 - Bump org.freemarker:freemarker from 2.3.34 to 2.3.35
  • #56349 - [3.39] Bump to Vert.x 4.5.33
  • #56573 - Bump aesh 3.18.0, add pipeline stage results, lazy runtime startup
  • #56783 - Typo fixes in gRPC guides
  • #56796 - docs: Fix the dead Jose4J link in the JWT Build guide
  • #56800 - Add javadoc to AbstractSecurityIdentityAssociation
  • #56821 - [3.40] SmallRye Fault Tolerance: bump to 6.11.4
  • #56831 - [3.40] Qute: EvalSectionHelper and StrEvalNamespaceResolver fixes
  • #56837 - Do not stack asciidoc anchors, because it does not work
  • #56838 - Fix malformed link
  • #56842 - Fix dead link for Redis sandbox
  • #56845 - Bump Keycloak version to 26.7.4
  • #56849 - [3.40] Upgrade RESTEasy to 6.2.19.Final
  • #56853 - [3.40] Upgrade to Hibernate 7.4.9.Final
  • #56857 - [3.40] WebSockets Next: add max-pending-messages back-pressure
  • #56861 - [3.40] Fix path normalization bypass on wildcard routes (matrix-param + dot-segment)
  • #56867 - [3.40] : Bump smallrye-jwt version to 4.6.4
  • #56884 - Invalid Java interface declaration in SmallRye GraphQL guide
  • #56885 - Fix interface inheritance in SmallRye GraphQL guide
  • #56920 - Update Elytron to 2.9.2.SP1
  • #56925 - aesh 3.18.1
Commits
  • 2b5f5ea [RELEASE] - Bump version to 3.40.0
  • a3c701a Merge pull request #56931 from gsmet/3.40.0-backports-2
  • 98242d4 aesh 3.18.1
  • e09ba0f Bump aesh 3.18.0, add pipeline stage results, lazy runtime startup
  • d1cfc49 Merge pull request #56905 from gsmet/3.40.0-backports-1
  • b6db218 Merge pull request #56831 from jmartisk/3.40-qute-xss
  • 6763c90 Fix interface inheritance in SmallRye GraphQL guide
  • 1a298a6 Bump Keycloak version to 26.7.4
  • 1371ddf Fix dead link for Redis sandbox
  • 6f6b621 Do not stack anchors, because it does not work
  • Additional commits viewable in compare view

Updates io.quarkus:quarkus-extension-processor from 3.39.4 to 3.40.0

Updates io.quarkus:quarkus-extension-maven-plugin from 3.39.4 to 3.40.0

Release notes

Sourced from io.quarkus:quarkus-extension-maven-plugin's releases.

3.40.0

Complete changelog

  • #56750 - Enhance CycloneDX documentation and configuration options description to stress the priority on JSON format
  • #56829 - [3.40] Update to Scalpel 0.4.2

3.40.0.CR1

Complete changelog

3.39.5

Complete changelog

  • #56037 - Always complete the export when the OTLP sender is shut down
  • #56255 - Bump org.freemarker:freemarker from 2.3.34 to 2.3.35
  • #56349 - [3.39] Bump to Vert.x 4.5.33
  • #56573 - Bump aesh 3.18.0, add pipeline stage results, lazy runtime startup
  • #56783 - Typo fixes in gRPC guides
  • #56796 - docs: Fix the dead Jose4J link in the JWT Build guide
  • #56800 - Add javadoc to AbstractSecurityIdentityAssociation
  • #56821 - [3.40] SmallRye Fault Tolerance: bump to 6.11.4
  • #56831 - [3.40] Qute: EvalSectionHelper and StrEvalNamespaceResolver fixes
  • #56837 - Do not stack asciidoc anchors, because it does not work
  • #56838 - Fix malformed link
  • #56842 - Fix dead link for Redis sandbox
  • #56845 - Bump Keycloak version to 26.7.4
  • #56849 - [3.40] Upgrade RESTEasy to 6.2.19.Final
  • #56853 - [3.40] Upgrade to Hibernate 7.4.9.Final
  • #56857 - [3.40] WebSockets Next: add max-pending-messages back-pressure
  • #56861 - [3.40] Fix path normalization bypass on wildcard routes (matrix-param + dot-segment)
  • #56867 - [3.40] : Bump smallrye-jwt version to 4.6.4
  • #56884 - Invalid Java interface declaration in SmallRye GraphQL guide
  • #56885 - Fix interface inheritance in SmallRye GraphQL guide
  • #56920 - Update Elytron to 2.9.2.SP1
  • #56925 - aesh 3.18.1
Commits
  • 2b5f5ea [RELEASE] - Bump version to 3.40.0
  • a3c701a Merge pull request #56931 from gsmet/3.40.0-backports-2
  • 98242d4 aesh 3.18.1
  • e09ba0f Bump aesh 3.18.0, add pipeline stage results, lazy runtime startup
  • d1cfc49 Merge pull request #56905 from gsmet/3.40.0-backports-1
  • b6db218 Merge pull request #56831 from jmartisk/3.40-qute-xss
  • 6763c90 Fix interface inheritance in SmallRye GraphQL guide
  • 1a298a6 Bump Keycloak version to 26.7.4
  • 1371ddf Fix dead link for Redis sandbox
  • 6f6b621 Do not stack anchors, because it does not work
  • Additional commits viewable in compare view

Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting @dependabot rebase.


Dependabot commands and options

You can trigger Dependabot actions by commenting on this PR:

  • @dependabot rebase will rebase this PR
  • @dependabot recreate will recreate this PR, overwriting any edits that have been made to it
  • @dependabot show <dependency name> ignore conditions will show all of the ignore conditions of the specified dependency
  • @dependabot ignore this major version will close this PR and stop Dependabot creating any more for this major version (unless you reopen the PR or upgrade to it yourself)
  • @dependabot ignore this minor version will close this PR and stop Dependabot creating any more for this minor version (unless you reopen the PR or upgrade to it yourself)
  • @dependabot ignore this dependency will close this PR and stop Dependabot creating any more for this dependency (unless you reopen the PR or upgrade to it yourself)

Bumps `quarkus.version` from 3.39.4 to 3.40.0.

Updates `io.quarkus:quarkus-bom` from 3.39.4 to 3.40.0
- [Release notes](https://github.com/quarkusio/quarkus/releases)
- [Commits](quarkusio/quarkus@3.39.4...3.40.0)

Updates `io.quarkus:quarkus-extension-processor` from 3.39.4 to 3.40.0

Updates `io.quarkus:quarkus-extension-maven-plugin` from 3.39.4 to 3.40.0
- [Release notes](https://github.com/quarkusio/quarkus/releases)
- [Commits](quarkusio/quarkus@3.39.4...3.40.0)

---
updated-dependencies:
- dependency-name: io.quarkus:quarkus-bom
  dependency-version: 3.40.0
  dependency-type: direct:production
  update-type: version-update:semver-minor
- dependency-name: io.quarkus:quarkus-extension-processor
  dependency-version: 3.40.0
  dependency-type: direct:production
  update-type: version-update:semver-minor
- dependency-name: io.quarkus:quarkus-extension-maven-plugin
  dependency-version: 3.40.0
  dependency-type: direct:development
  update-type: version-update:semver-minor
...

Signed-off-by: dependabot[bot] <support@github.com>
@dependabot dependabot Bot added dependencies Pull requests that update a dependency file java Pull requests that update java code labels Oct 1, 2026

This branch has not been deployed

No deployments
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

dependencies Pull requests that update a dependency file java Pull requests that update java code

Projects

None yet

Development

Successfully merging this pull request may close these issues.

0 participants