Skip to content

chore(deps): bump com.diffplug.spotless:spotless-maven-plugin from 3.8.0 to 3.10.3 - #3639

Open
dependabot[bot] wants to merge 1 commit into
mainfrom
dependabot/maven/com.diffplug.spotless-spotless-maven-plugin-3.10.3
Open

dependabot[bot] wants to merge 1 commit into
mainfrom
dependabot/maven/com.diffplug.spotless-spotless-maven-plugin-3.10.3

Conversation

@dependabot

@dependabot dependabot Bot commented on behalf of github Sep 29, 2026

Copy link
Copy Markdown
Contributor

Bumps com.diffplug.spotless:spotless-maven-plugin from 3.8.0 to 3.10.3.

Release notes

Sourced from com.diffplug.spotless:spotless-maven-plugin's releases.

Maven Plugin v3.10.3

Changes

  • Generate formatter defaults from version catalog. (#3045)
  • Bump default gson version 2.13.2 -> 2.14.0. (#3045)
  • Bump default zjsonpatch version 0.4.14 -> 0.4.16. (#3045)
  • Bump default jackson-dataformat-yaml version 2.14.1 -> 2.20.1. (#3045)
  • Bump default ktfmt version 0.63 -> 0.64. (2988)
  • Bump default cleanthat version 2.25 -> 2.26. (#2882)
  • Bump default jackson version 2.20.1 -> 2.22.2. (#2819)
  • Bump default javaparser version 3.27.1 -> 3.28.2. (#3065)
  • Bump default palantir-java-format version 2.80.0 -> 2.98.0. (#3068)
  • Bump default scalafmt version 3.8.1 -> 3.11.5. (#2173)
  • Bump default google-java-format version 1.30.0 -> 1.36.1. (#3075)
  • Bump default gherkin-utils version 10.0.0 -> 12.0.2. (#2979)

Fixed

  • Fix release signing by using Gradle's required eight-digit signing subkey ID. (#3105)
  • Fix race when creating the npm install cache directory. ((#3096)
  • GrEclipse no longer emits expected OSGi and nested-jar warnings during initialization. (#2445)
  • typescript prettier() no longer emits a warning when its parser is already set to typescript. (#3098)
  • <versionCatalog> preserves standalone comments at section boundaries and the end of the file. (#3048)
  • <versionCatalog> preserves entries when comments contain unmatched brackets, preserves commas inside quoted strings, and keeps significant line boundaries in multiline entries. (#3042)
  • <versionCatalog> now reports unfinished entries as lints at their starting line. These fail formatting by default, so upgrading may expose catalog errors that previously caused silent data loss. (#3042)
  • Eclipse JDT formatter step no longer fails with NoClassDefFoundError or NoSuchMethodError when lombok is active as a JVM agent (e.g. -javaagent:lombok.jar in Eclipse/VS Code/Cursor). (#2795)

Maven Plugin v3.10.2

Fixed

  • <shortenFullyQualifiedTypes> now shortens fully-qualified types used in expression contexts (such as static method calls, static fields, and enum constants) while avoiding imports that would change how existing unqualified type references resolve. (#3039)
  • Eclipse JDT formatter step no longer fails with NoClassDefFoundError when lombok is active as a JVM agent (e.g. -javaagent:lombok.jar in Eclipse/VS Code/Cursor). (#2795)

Maven Plugin v3.10.1

Fixed

  • <prettier> and other npm-based steps no longer fail to start on npm 12 (EUNKNOWNCONFIG from --scripts-prepend-node-path). (#3024)

Maven Plugin v3.10.0

Added

  • New <shortenFullyQualifiedTypes> step for Java, which replaces fully-qualified type names with their simple names and adds the imports they need. Best combined with <importOrder> and <removeUnusedImports>. (#2945)
  • Add embedded lockfiles to Eclipse JDT for every supported version (4.9 through 4.40), so eclipse() resolves from Maven Central instead of querying a P2 update site. Versions without an embedded lockfile still fall back to P2 provisioning. (#1996)
  • Add support to apply alternate license header within same format (#872)
  • Add support to skip license header application based on source file content pattern (#650).

Fixed

  • removeUnusedImports no longer fails on Java import module declarations. (#2890)
  • Concurrent P2 provisioning no longer races Solstice's on-disk cache (affects Eclipse-based formatters under parallel builds). (#3004)

Changes

  • Default google-java-format remains 1.28.0 on JVM 17; bumps to 1.30.0 on JVM 21+; require at least 1.30.0 on JVM 25+ for import module support.
  • Bump default eclipse version to latest 4.39 -> 4.40. (#1996)
  • Document Maven skip properties spotless.skip, spotless.check.skip, and spotless.apply.skip. Goal-specific skips now live on their own mojos so they no longer leak across goals. (#3009)
  • Bump default adocfmt version 0.2.0 -> 0.3.1, which adds table formatting support (<formatTables>, <tableLayout>, <tableMaxLineWidth>, <tableBlankLines>).

Maven Plugin v3.9.0

... (truncated)

Commits
  • 61e2016 Published maven/3.10.3
  • 49e0b07 Published lib/4.10.3
  • b7a7748 Fix release signing key ID format (#3105)
  • be8005a Document release signing correction (#3105)
  • 073fe61 Use short signing subkey ID for release publishing
  • 8ac44c7 Fix race when creating the npm install cache directory (#3096)
  • 3f2d955 Update dependency org.slf4j:slf4j-api to v2.0.20 (#3100)
  • 0c70ca8 Merge branch 'main' into fix/npm-cache-directory-race
  • bbf44a4 Fix GrEclipse initialization warnings (#3097)
  • b6bdcd0 Update dependency org.slf4j:slf4j-api to v2.0.20
  • Additional commits viewable in compare view

Dependabot compatibility score

Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting @dependabot rebase.


Dependabot commands and options

You can trigger Dependabot actions by commenting on this PR:

  • @dependabot rebase will rebase this PR
  • @dependabot recreate will recreate this PR, overwriting any edits that have been made to it
  • @dependabot show <dependency name> ignore conditions will show all of the ignore conditions of the specified dependency
  • @dependabot ignore this major version will close this PR and stop Dependabot creating any more for this major version (unless you reopen the PR or upgrade to it yourself)
  • @dependabot ignore this minor version will close this PR and stop Dependabot creating any more for this minor version (unless you reopen the PR or upgrade to it yourself)
  • @dependabot ignore this dependency will close this PR and stop Dependabot creating any more for this dependency (unless you reopen the PR or upgrade to it yourself)

Bumps [com.diffplug.spotless:spotless-maven-plugin](https://github.com/diffplug/spotless) from 3.8.0 to 3.10.3.
- [Release notes](https://github.com/diffplug/spotless/releases)
- [Changelog](https://github.com/diffplug/spotless/blob/main/CHANGES.md)
- [Commits](diffplug/spotless@maven/3.8.0...maven/3.10.3)

---
updated-dependencies:
- dependency-name: com.diffplug.spotless:spotless-maven-plugin
  dependency-version: 3.10.3
  dependency-type: direct:production
  update-type: version-update:semver-minor
...

Signed-off-by: dependabot[bot] <support@github.com>
@dependabot dependabot Bot added dependencies Pull requests that update a dependency file java Pull requests that update Java code labels Sep 29, 2026
Copilot AI balanced review requested due to automatic review settings September 29, 2026 03:32
@dependabot dependabot Bot added dependencies Pull requests that update a dependency file java Pull requests that update Java code labels Sep 29, 2026
@openshift-ci
openshift-ci Bot requested review from csviri and xstefank September 29, 2026 03:32
@coderabbitai

coderabbitai Bot commented Sep 29, 2026

Copy link
Copy Markdown

Important

Review skipped

Bot user detected.

To trigger a single review, invoke the @coderabbitai review command.

⚙️ Run configuration

Configuration used: defaults

Review profile: CHILL

Plan: Advanced

Run ID: f422f0b9-b142-4af5-847e-e2c6845f98ed

You can disable this status message by setting the reviews.review_status to false in the CodeRabbit configuration file.

Use the checkbox below for a quick retry:

  • 🔍 Trigger review

Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out.

❤️ Share

Comment @coderabbitai help to get the list of available commands.

Copilot AI left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Copilot review overview

🟢 Approval recommended

The consistent version-only upgrade introduces no apparent configuration or compatibility issues.

Review effort: Balanced
Findings: None

What changed in this PR

Updates the Spotless Maven plugin to 3.10.3 across the project.

Changes:

  • Upgrades the root build from 3.8.0.
  • Upgrades the BOM build from 3.9.0.
File Description
pom.xml Updates the root Spotless plugin version.
operator-framework-bom/​pom.xml Aligns the BOM’s Spotless plugin version.

💡 Add a code-review agent skill or configure MCP servers for context-aware, tailored reviews. Learn more in the docs.

This branch has not been deployed

No deployments
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

dependencies Pull requests that update a dependency file java Pull requests that update Java code

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant