Skip to content

Bump io.github.classgraph:classgraph from 4.8.195 to 4.8.196 - #255

Merged
simoc merged 1 commit into
masterfrom
dependabot/maven/io.github.classgraph-classgraph-4.8.196
Sep 28, 2026
Merged

simoc merged 1 commit into
masterfrom
dependabot/maven/io.github.classgraph-classgraph-4.8.196

Conversation

@dependabot

@dependabot dependabot Bot commented on behalf of github Sep 28, 2026

Copy link
Copy Markdown
Contributor

Bumps io.github.classgraph:classgraph from 4.8.195 to 4.8.196.

Release notes

Sourced from io.github.classgraph:classgraph's releases.

ClassGraph 4.8.196

ClassGraph 5.0.0 is coming shortly, and requires JDK 17 or newer. 4.8.196 is a bugfix release on the 4.x maintenance branch, and continues the file-by-file audit that produced 4.8.190 through 4.8.195. As before, most of the bugs listed here were found by Claude through careful code analysis, and were fixed on the v5 branch and backported to v4.

Mocking the list classes with mockk works again (#945)

Since 4.8.185, mockk failed to mock ResourceList, ClassInfoList and the other list classes, with "class redefinition failed: attempted to add a method". These classes extend a package-private class, and releases since 4.8.185 were built with JDK 8, whose javac does not emit public bridge methods in the public subclass for add(T), add(int, T), remove(int) and set(int, T). The list classes now declare these methods themselves, so they are present whichever JDK builds the release.

Bug fixes: classpath elements and jarfiles

  • The context classloader could be moved behind the application classloader. The classloaders found in the environment were sorted by descending delegation depth, so that a classloader is searched before its ancestors. That also put any classloader with more ancestors ahead of an unrelated one with fewer -- the application classloader ahead of a context classloader with no parent, for example -- although the context classloader is meant to be tried first. Each classloader is now inserted just ahead of the first of its ancestors that is already listed, which keeps descendants ahead of ancestors and otherwise keeps the preference order.

  • Class-Path and Bundle-ClassPath manifest attributes are now read with their specified syntax. A Class-Path entry is a relative URL, so its percent encoding is now decoded, as the JVM's own classloader decodes it. Before, a jarfile written as my%20lib.jar was looked for under that literal name, so a jarfile with a space in its name could not be named at all. Bundle-ClassPath paths are now trimmed, unquoted and separated from their parameters, following the OSGi header syntax. Before, . , inner.jar named inner.jar, and a quoted path or one with a parameter named nothing that exists.

  • When a zipfile has two entries with the same name, the last one is now used, as the JDK does. ClassGraph kept the first, so a scan could report a different resource, and open a different nested jarfile, than the JVM would load.

  • META-INF/versions/09/ is no longer read as multi-release version 9. The JDK looks up versioned entries only under the plain decimal version number, so ClassGraph could report a class that the JVM never loads.

  • The file of a nested jarfile is now always the outermost jarfile. It was the outer jarfile if the nested jarfile was stored, but null or a temporary file if it was deflated. ScanResult#getClasspathFiles() lists the outer jarfile once, however many jarfiles are nested within it.

  • A zipfile with an Info-ZIP Unicode path extra field of a version other than 1 could not be read. java.util.zip.ZipFile opens such a file, since the JDK does not read that field. The field is now logged and ignored.

  • A large nested jar with a long name could not be opened. A nested jar too large to hold in RAM is written to a temporary file named after its zip entry, and a long entry name made File.createTempFile fail with "File name too long". The name is now cut to its last 64 characters.

  • A jarfile URL that redirected from http to https failed with "Got response code 301", since HttpURLConnection only follows a redirect that keeps the same scheme. Redirects are now followed, up to 20 times. A redirect from https to http, or to a scheme that has not been enabled, is refused.

  • A SecurityManager that refused to let ClassGraph read a file's attributes stopped the scan of the rest of that directory. Only that file is now skipped.

  • The Quarkus classloader handler failed the whole scan when a field it reads held a null or unexpected value. Such elements are now skipped.

  • normalizePath did not collapse // in a path that did not end with a separator, so a//b stayed a//b while a//b/ became a/b.

Bug fixes: memory, file handles and temporary files

  • A file is no longer memory-mapped when it could not be unmapped again. A SecurityManager that denied access to the buffer cleaner made new ClassGraph() throw "Cannot get buffer cleaner method". Now, below JDK 22, a file is only memory-mapped when the cleaner is available, since otherwise the mapping, and on Windows the file lock, would last until the buffer was garbage collected.

  • A canceled scanAsync future leaked its ScanResult. A result that arrived after the future was canceled was never handed to anyone, so nothing closed it. It is now closed. The call stack and context classloader are still read on the calling thread, but the jarfiles are now opened when the task runs, so a task that is canceled before it starts opens nothing.

  • Temporary files no longer use deleteOnExit(). Closing the scan already deletes every temporary file, so deleteOnExit() only made the JDK hold every temporary path until the JVM exited.

  • A module reader could be left open if it was returned to its pool at the same moment the pool was being force-closed.

  • Reading a stream of declared length allocated a buffer of that whole length up front, up to the maximum buffered jar size. The first buffer is now at most 16MB, and grows as data arrives. A related method doubled its buffer whenever a read returned zero bytes, even when the buffer was not full; no scan was affected, since the streams it is given never return zero.

  • A refused unmap of a buffer view was logged as "Could not unmap ByteBuffer: java.lang.reflect.InvocationTargetException". Such a view is now refused without a log entry, and any other failure is logged with its real cause.

Bug fixes: the class graph

  • ClassInfo#isAnonymousInnerClass() returned true for named local classes. It now agrees with Class#isAnonymousClass(). getFullyQualifiedDefiningMethodName() returned <clinit> for a class declared in an instance initializer or an instance field initializer, which javac compiles into the constructors; it now returns null for these, as Class#getEnclosingMethod() does.

  • A local record, enum or interface was reported as not static.

... (truncated)

Commits
  • 8f16afe [maven-release-plugin] prepare release classgraph-4.8.196
  • f0f3d2d Declare the element methods in the public list classes, so mockk can mock the...
  • a4d872d [maven-release-plugin] prepare for next development iteration
  • 495b196 [maven-release-plugin] prepare release classgraph-4.8.196
  • 4d08ea2 Keep a '$' after a '.' in a class reference as part of the nested class name
  • 67c7d33 Follow an http to https redirect when downloading a jarfile
  • b8d2225 Check in the LocalRecordTest classfile fixtures, which .gitignore excluded
  • 1eb2fb2 Make AnnotationParameterValue.equals and hashCode agree with compareTo for un...
  • 707fea6 Resolve type variables of an enclosing class, and tell a method's type variab...
  • 534d034 Report local records as static, and fix type annotations on local class const...
  • Additional commits viewable in compare view

Dependabot compatibility score

Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting @dependabot rebase.


Dependabot commands and options

You can trigger Dependabot actions by commenting on this PR:

  • @dependabot rebase will rebase this PR
  • @dependabot recreate will recreate this PR, overwriting any edits that have been made to it
  • @dependabot show <dependency name> ignore conditions will show all of the ignore conditions of the specified dependency
  • @dependabot ignore this major version will close this PR and stop Dependabot creating any more for this major version (unless you reopen the PR or upgrade to it yourself)
  • @dependabot ignore this minor version will close this PR and stop Dependabot creating any more for this minor version (unless you reopen the PR or upgrade to it yourself)
  • @dependabot ignore this dependency will close this PR and stop Dependabot creating any more for this dependency (unless you reopen the PR or upgrade to it yourself)

Bumps [io.github.classgraph:classgraph](https://github.com/classgraph/classgraph) from 4.8.195 to 4.8.196.
- [Release notes](https://github.com/classgraph/classgraph/releases)
- [Commits](classgraph/classgraph@classgraph-4.8.195...classgraph-4.8.196)

---
updated-dependencies:
- dependency-name: io.github.classgraph:classgraph
  dependency-version: 4.8.196
  dependency-type: direct:production
  update-type: version-update:semver-patch
...

Signed-off-by: dependabot[bot] <support@github.com>
@dependabot dependabot Bot added dependencies Pull requests that update a dependency file java Pull requests that update Java code labels Sep 28, 2026
@simoc
simoc merged commit fbba2a8 into master Sep 28, 2026
2 checks passed
@dependabot
dependabot Bot deleted the dependabot/maven/io.github.classgraph-classgraph-4.8.196 branch September 28, 2026 07:31
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

dependencies Pull requests that update a dependency file java Pull requests that update Java code

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant