Skip to content

build(deps): WW-5764 bump com.github.ben-manes.caffeine:caffeine from 3.2.4 to 3.3.0 - #1995

Merged
lukaszlenart merged 1 commit into
mainfrom
dependabot/maven/main/com.github.ben-manes.caffeine-caffeine-3.3.0
Oct 7, 2026
Merged

lukaszlenart merged 1 commit into
mainfrom
dependabot/maven/main/com.github.ben-manes.caffeine-caffeine-3.3.0

Conversation

@dependabot

@dependabot dependabot Bot commented on behalf of github Oct 7, 2026 •

Copy link
Copy Markdown
Contributor

Bumps com.github.ben-manes.caffeine:caffeine from 3.2.4 to 3.3.0.

Closes WW-5764

Release notes

Sourced from com.github.ben-manes.caffeine:caffeine's releases.

3.3.0

  • Improved read performance by avoiding false sharing in the fast-path check
  • Improved adaptive climber for small caches and shifting workloads
  • Fixed various minor issues found using AI audits
  • Fixed over-aggressive refresh discard (#1970)
Commits
  • af86011 fix jcache audit triage
  • f063e56 Prevent overflow in snapshot durations
  • 5b6fbd9 Saturate the audit stillness counter
  • 48cb408 Read lazy cache views and policies once
  • 4978d18 Normalize JCache processor loader failures
  • c9038d8 Consume JCache iterator removals before listener failures
  • 0b0afd2 polish
  • c0edd00 restore coverage lost to recent fixes
  • 5283c96 make CLOCK-Pro's cold hand a setting
  • d15c205 make the bulk cache loaders serializable
  • Additional commits viewable in compare view

Dependabot compatibility score

Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting @dependabot rebase.


Dependabot commands and options

You can trigger Dependabot actions by commenting on this PR:

  • @dependabot rebase will rebase this PR
  • @dependabot recreate will recreate this PR, overwriting any edits that have been made to it
  • @dependabot show <dependency name> ignore conditions will show all of the ignore conditions of the specified dependency
  • @dependabot ignore this major version will close this PR and stop Dependabot creating any more for this major version (unless you reopen the PR or upgrade to it yourself)
  • @dependabot ignore this minor version will close this PR and stop Dependabot creating any more for this minor version (unless you reopen the PR or upgrade to it yourself)
  • @dependabot ignore this dependency will close this PR and stop Dependabot creating any more for this dependency (unless you reopen the PR or upgrade to it yourself)

Bumps [com.github.ben-manes.caffeine:caffeine](https://github.com/ben-manes/caffeine) from 3.2.4 to 3.3.0.
- [Release notes](https://github.com/ben-manes/caffeine/releases)
- [Commits](ben-manes/caffeine@v3.2.4...v3.3.0)

---
updated-dependencies:
- dependency-name: com.github.ben-manes.caffeine:caffeine
  dependency-version: 3.3.0
  dependency-type: direct:production
  update-type: version-update:semver-minor
...

Signed-off-by: dependabot[bot] <support@github.com>
@dependabot dependabot Bot added dependencies Pull requests that update a dependency file java Pull requests that update Java code labels Oct 7, 2026
@lukaszlenart lukaszlenart changed the title build(deps): bump com.github.ben-manes.caffeine:caffeine from 3.2.4 to 3.3.0 build(deps): WW-5764 bump com.github.ben-manes.caffeine:caffeine from 3.2.4 to 3.3.0 Oct 7, 2026
@lukaszlenart
lukaszlenart merged commit 44201d5 into main Oct 7, 2026
13 of 14 checks passed
@lukaszlenart
lukaszlenart deleted the dependabot/maven/main/com.github.ben-manes.caffeine-caffeine-3.3.0 branch October 7, 2026 10:08
opensource-fork-sync Bot pushed a commit to cla7aye15I4nd/opensource-apache__struts that referenced this pull request Oct 7, 2026
Lessons from the 2026-10-07 queue run (apache#1995-apache#2000):

- Step 5 no longer resolves the ticket; it reports it as ready to resolve.
  The ticket workflow belongs to the release manager.
- The fix version comes from the latest tickets on the line, not the pom:
  support/struts-6-x-x reads 6.12.1-SNAPSHOT while its next release is 6.13.0,
  and 7.4.0 is still unreleased in Jira after shipping.
- The Closes line anchors on the Bumps line; bodies without release notes have
  no <details> before the commands footer.
- A red bump that is deferred gets a ticket at the next major and a closing
  comment with `@dependabot ignore this major version` (apache#1905, apache#1998).
- The twin check also searches Jira, since a twin may have merged in an
  earlier run.

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

dependencies Pull requests that update a dependency file java Pull requests that update Java code

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant