Skip to content

Comments

Bump io.zipkin.brave:brave-bom from 5.13.11 to 5.18.1#3677

Open
dependabot[bot] wants to merge 1 commit intomainfrom
dependabot/maven/io.zipkin.brave-brave-bom-5.18.1
Open

Bump io.zipkin.brave:brave-bom from 5.13.11 to 5.18.1#3677
dependabot[bot] wants to merge 1 commit intomainfrom
dependabot/maven/io.zipkin.brave-brave-bom-5.18.1

Conversation

@dependabot
Copy link
Contributor

@dependabot dependabot bot commented on behalf of github Feb 23, 2026

Bumps io.zipkin.brave:brave-bom from 5.13.11 to 5.18.1.

Release notes

Sourced from io.zipkin.brave:brave-bom's releases.

Brave 5.18 prepares for Brave 6 by deprecating instrumentation for libraries not released in 1.5-3.5 years including:

  • context/rxjava2 - last released Feb 2021
    • replaced by RxJava3, but unlikely this module will be ported as it wasn't used widely.
  • instrumentation/dubbo-rpc - (alibaba) last released Dec 2021
    • replaced by Apache Dubbo instrumentation/dubbo
  • instrumentation/p6spy - last released July 2020
    • project dormant
  • instrumentation/sparkjava - last released July 2022
    • project dormant

A minor change is we changed the artifact we use to test MySQL 8 to com.mysql:mysql-connector-j (instead of mysql:mysql-connector-java), to ensure we validate against current versions. Thanks @​m1ngyuan for the help on this.

Full Changelog: https://github.com/openzipkin/brave/compare/5.17.1..5.18.1

Brave 5.17.1

Brave v5.17.1 fixes a bug where the jars that should be at Java 1.6 or 1.7 bytecode were not.

Full Changelog: https://github.com/openzipkin/brave/compare/5.17.0..5.17.1

Brave 5.17.0 updates all versions to latest and renovates the build so that it can work on JDK21. Thanks in particular to @​ShenFeng312 for work updating to Dubbo 3.

It also changes the brave-tests dependency to rely on junit-jupiter instead of junit 4, removing rev-locks and CVE warnings from downstream users. Jupiter was assisted by OpenRewrite automated refactoring by @​TeamModerne.

Thanks finally, to those who helped with maintenance, bugs and test backfilling in the last 6 months including @​JochemKuijpers @​sprimonk @​strehle @​mauhiz @​1derian @​charley-zhang @​pen4 @​rewolf @​mustafau and @​jcchavezs

Full Changelog: https://github.com/openzipkin/brave/compare/5.16.0..5.17.0

Brave 5.16.0

What's Changed

New Contributors

Full Changelog: openzipkin/brave@5.15.1...5.16.0

Brave 5.15.1

What's Changed

New Contributors

... (truncated)

Commits
  • a50e658 [maven-release-plugin] prepare release 5.18.1
  • 67b6013 deps: reverts to zipkin-reporter 2.x (#1403)
  • 5c977a2 Temporarily revert brave 6 change
  • f99265d bump to 6.0.0-SNAPSHOT
  • 44e4081 Removes all deprecated types and modules for Brave v6 (#1395)
  • 50c2892 [maven-release-plugin] prepare for next development iteration
  • 2150058 [maven-release-plugin] prepare release 5.18.0
  • ad39719 Qualifies that KeyFactory and Propagation.Factory.create will go in Brave 7 (...
  • 73687f1 deps: updates to zipkin-reporter 3.0.0 (#1399)
  • 169b575 Undeprecates propagation symbols for v6 interop (#1396)
  • Additional commits viewable in compare view

Most Recent Ignore Conditions Applied to This Pull Request
Dependency Name Ignore Conditions
io.zipkin.brave:brave-bom [>= 6.a0, < 7]

Dependabot compatibility score

Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting @dependabot rebase.


Dependabot commands and options

You can trigger Dependabot actions by commenting on this PR:

  • @dependabot rebase will rebase this PR
  • @dependabot recreate will recreate this PR, overwriting any edits that have been made to it
  • @dependabot show <dependency name> ignore conditions will show all of the ignore conditions of the specified dependency
  • @dependabot ignore this major version will close this PR and stop Dependabot creating any more for this major version (unless you reopen the PR or upgrade to it yourself)
  • @dependabot ignore this minor version will close this PR and stop Dependabot creating any more for this minor version (unless you reopen the PR or upgrade to it yourself)
  • @dependabot ignore this dependency will close this PR and stop Dependabot creating any more for this dependency (unless you reopen the PR or upgrade to it yourself)

Bumps [io.zipkin.brave:brave-bom](https://github.com/openzipkin/brave) from 5.13.11 to 5.18.1.
- [Release notes](https://github.com/openzipkin/brave/releases)
- [Changelog](https://github.com/openzipkin/brave/blob/master/RELEASE.md)
- [Commits](openzipkin/brave@5.13.11...5.18.1)

---
updated-dependencies:
- dependency-name: io.zipkin.brave:brave-bom
  dependency-version: 5.18.1
  dependency-type: direct:production
  update-type: version-update:semver-minor
...

Signed-off-by: dependabot[bot] <support@github.com>
@dependabot dependabot bot added the type: dependency-upgrade A dependency upgrade label Feb 23, 2026
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

type: dependency-upgrade A dependency upgrade

Projects

None yet

Development

Successfully merging this pull request may close these issues.

0 participants