Skip to content

Update dependency io.helidon:helidon-dependencies to v27 - #241

Open
renovate[bot] wants to merge 1 commit into
masterfrom
renovate/major-helidon
Open

renovate[bot] wants to merge 1 commit into
masterfrom
renovate/major-helidon

Conversation

@renovate

@renovate renovate Bot commented Sep 18, 2026 •

Copy link
Copy Markdown
Contributor

ℹ️ Note

This PR body was truncated due to platform limits.

This PR contains the following updates:

Package Change Age Confidence
io.helidon:helidon-dependencies (source) 4.5.5 → 27.0.0 age confidence

Release Notes

helidon-io/helidon (io.helidon:helidon-dependencies)

v27.0.0

Compare Source

This is a major release of Helidon. Helidon 27 is the first Helidon release to fully adopt the
JDK Tip & Tail software development model. Helidon releases will
now align with JDK releases and the minimum Java requirement will bump to match the corresponding
JDK release.

Helidon 27 is a feature release. Helidon 4 is considered an LTS release. Helidon 29
will be the next LTS release.

A minimum of Java 27 is required to use Helidon 27.

NOTABLE CHANGES
  1. MicroProfile support has moved from the core Helidon repository into its own project.
    Helidon MicroProfile is not part of the
    Helidon 27 release. It will release independently in the near future.
  2. Extensions (integrations) have moved to the Helidon Extensions
    repository and each extension will have its own release lifecycle.
  3. HTTP method names and method selectors are now case-sensitive. Update ordinary built-in method names in configuration
    and application code to their standard uppercase form, such as GET instead of get. Security configuration temporarily
    also matches the uppercase form of known methods configured in lowercase or mixed case, and logs a migration warning.
    This compatibility will be removed in a future major version. See the
    27 upgrade guide for affected configuration areas.
  4. Helidon 27 contains multiple third party dependency upgrades. Some that might impact backwards compatibility:
    • OpenTelemetry 1.65.0
    • Micrometer 1.17.1

For more information see the 27 upgrade guide.

NOTABLE NEW FEATURES
  1. Helidon Data JDBC (Incubating)
  2. Helidon Message (Preview)
  3. Helidon Declarative is feature complete. (Preview)
CHANGES
  • Builders: Add listener transport binding abstraction 12092
  • Builders: Add sealed support for prototype generated interfaces 12524
  • Builders: Annotate Builder APIs with API stability 12528
  • Builders: API stability processor and API 11184
  • Builders: Apply container semantics to TypeHandlerOptional 11970
  • Builders: Builder method setValues adjusted 11774
  • Builders: Enforce module descriptor conventions 12581
  • Builders: Fix array formatting in generated builder toString methods 12552
  • Builders: Fix builder codegen to correctly handle provider "discoverServices" 11429
  • Builders: Fix builder generic type variable handling 11793
  • Builders: Fix cross-package blueprint schema resolution 12246
  • Builders: Resolve deprecations in module helidon-builder 11496
  • Builders: Resolve deprecations in module helidon-common-types 11514
  • Builders: Support Optional<List> for provider-backed builder options 11840
  • Codegen: Add validation codegen tests#11372 11786
  • Codegen: Annotate Codegen APIs with API stability 12530
  • Codegen: API stability annotations follow up 11802
  • Codegen: Defer API stability checks until final round 11569
  • Codegen: Fix API stability record constructor errors on JDK 26 (main) 12135
  • Codegen: Fix codegen TypeName annotation handling 11874
  • Codegen: Fix declarative request parameter codegen 11745
  • Codegen: Fix inherited declarative contract annotations 12156
  • Codegen: Fix raw types in declarative code generator 11551
  • Codegen: Fix validated interface codegen switch 11863
  • Codegen: Fixes type use annotations issue 11555
  • Codegen: Forward-port declarative validation constraints from service interfaces 12036
  • Codegen: Honor record components and type mappers in codegen APT 11574
  • Codegen: Resolve deprecations in module helidon-codegen-apt 11499
  • Codegen: Resolve deprecations in module helidon-codegen 11497
  • Codegen: Resolve deprecations in module helidon-codegen-class-model 11632
  • Common: Add non-mutating LRU cache lookup 12385
  • Common: Add read-only buffer slicing support 12258
  • Common: Add stuck thread detection 12183
  • Common: Add TOML media type 12082
  • Common: Add URI host and authority normalization 12046
  • Common: Annotate Common APIs with API stability 12527
  • Common: Defensively copy TLS SSL parameters 11890
  • Common: Deprecate BufferData#asInputStream() 12076
  • Common: Enforce read-only buffer logical bounds 12249
  • Common: Expose TLS reload generation 12273
  • Common: Fix BufferData lastIndexOf index handling 11903
  • Common: Fix invalid feature flavor metadata 11898
  • Common: Fix ListContext unregister identity handling 11907
  • Common: Fix MapperManager service caching 11404
  • Common: Fix OutputStreamMulti buffer size for write(byte[], off, len) 11536
  • Common: Fix resolved URI query parameters 12243
  • Common: Fix smart socket writer 11895
  • Common: Fix thread pool keep-alive duration conversion 11881
  • Common: Fix TLS reload without initial managers 11885
  • Common: Fix virtual threads testing module name 11949
  • Common: Fix writeTo(OutputStream) writing excess bytes after partial read 11738
  • Common: Guard null context class loader lookups 12371
  • Common: NioSocket partial read 11386
  • Common: Preserve malformed percent sequences in URI decoding 11910
  • Common: Propagate idle socket monitor failures as I/O errors 12342
  • Common: Protect cached HTTP header bytes 569c6dafbc
  • Common: Reject malformed HPACK integers 9b37113593
  • Common: Reject negative LruCache capacity 12509
  • Common: Reject relative request targets at the protocol boundary 12384
  • Common: Reloadable TLS 12079
  • Common: Remove concurrency limits deprecated APIs and fix a few issues 11682
  • Common: Remove declarative ignore-incubating option 12523
  • Common: Remove deprecated types from common mapper. 11409
  • Common: Remove TemporaryFolderExt 11779
  • Common: Replace usage of io.helidon.build.common.test.utils.JUnitLauncher with EngineKit 11351
  • Common: Resolve deprecations in module helidon-common-buffers 11459
  • Common: Resolve deprecations in module helidon-common-context 11505
  • Common: Resolve deprecations in module helidon-common-key-util 11508
  • Common: Resolve deprecations in module helidon-common-reactive 11509
  • Common: Resolve deprecations in module helidon-common-socket 11512
  • Common: Resolve deprecations in module helidon-common 11501
  • Common: Resolve deprecations in module helidon-common-features-api 11507
  • Common: Resolve deprecations in module helidon-common-mapper 11623
  • Common: Share HPACK and QPACK Huffman codec 12289
  • Common: Share HTTP prefixed integer codec 12248
  • Common: Smile implementation 11754
  • Common: Update Context implementation to use ScopedValue 11693
  • Common: Validate custom HTTP status reason phrases b4caedba6c
  • Config: Accept legacy const sampler type configuration 12368
  • Config: Add method for use of deprecated config setting without a non-deprecated replacement 12359
  • Config: Balance Javadoc HTML in config schema descriptions 12255
  • Config: Config value encryption format strengthened ec2a8d2b71
  • Config: Deprecate ConfigUserStore constructor 12347
  • Config: Enable Javadoc fail-on-warning for config modules 11965
  • Config: Expand config observer secret masking defaults e0e7567f88
  • Config: Fix config docs logging initialization 12503
  • Config: Fix config polling recovery after reload failure 12114
  • Config: Fix helidon-config-metadata modules 11751
  • Config: Fix listener and provider configuration compatibility 12240
  • Config: Fix ordering in config ProvidedUtil 11336
  • Config: Fix OTLP self-tracing in packaging sample 11781
  • Config: HOCON parser fails to resolve included self-references and unresolved… 12120
  • Config: Make config observer secret masking case-insensitive 5acf29991c
  • Config: Mark ServiceLoader constructors internal 11758
  • Config: Mask unsafe config observe values c1df7ed94c
  • Config: Move declarative configuration to preview and support @​Configuration.Value expressions 11824
  • Config: Preserve generic config value mapper types 12107
  • Config: Replace internal usage of Config.map and Config.mapList 11304
  • Config: Resolve deprecations in module helidon-common-tls 11513
  • Config: Resolve deprecations in module helidon-common-configurable 11504
  • Config: Resolve deprecations in module helidon-config 11518
  • Config: Resolve deprecations in module helidon-config-metadata 11519
  • Config: Restore env-backed nested config nodes 11545
  • Config: Support char[] in @​Configuration.Value injection 12272
  • Config: Support disabled protocol configurations 12263
  • Config: Treeify config metadata docs around resolver nodes 11669
  • Config: upgrade jackson, typesafe-config, snakeyaml 11998
  • Config: Validate explicit SSLContext configuration 12242
  • CORS: Reject wildcard CORS credentials d37f3cb364
  • CORS: Restore default-port CORS origin matching 12512
  • Data: Fix generated data repository deprecation warning 11809
  • Data: Fix generated JPA and Java 27 dependency warnings 12580
  • Data: Helidon Data JDBC - implementation of declarative and imperative APIs 12232
  • Data: hikari 7.1.0 12354
  • Data: Strengthen JDBC repository return type validation 12560
  • DBClient: Apply DbMapper to MongoDB DML statements 11407
  • DBClient: Correct JPMS module names 12346
  • DBClient: Enable dbclient Javadoc fail on warning 11977
  • DBClient: Validate MongoDB numeric statement parameters b5a1249c7d
  • Declarative: Add class-level declarative media types 12253
  • Declarative: Add declarative CookieParam, FormParam, and RequestParams support 12035
  • Declarative: Fix explicit classloader loading for HTTP parameter providers 11662
  • Declarative: Reject missing declarative request entities 12148
  • Declarative: Reject private declarative fallback methods 11602
  • FaulTolerance: Remove deprecated FaultTolerance helpers 11525
  • FT: Fix bulkhead waiting metric accounting 11432
  • FT: Fix timeout current-thread completion logging 11790
  • FT: Generalize fault tolerance retry handling 12507
  • FT: Settle Async result futures on cancellation 12510
  • GraphQL: Add declarative GraphQL 12123
  • GraphQL: Enable custom values to be added to the ExecutionContext in graphql calls 11855
  • GraphQL: Fix GraphQL query depth and complexity limits 9290febf14
  • GraphQL: Require GraphQL authentication by default 6127dec685
  • gRPC: Add declarative gRPC support 12124
  • gRPC: Add WebServer gRPC security integration 601ae0cbc7
  • gRPC: Align gRPC inbound message size handling 12534
  • gRPC: Align gRPC routing builder c6a48f9e4f
  • gRPC: implement Drainable, skip, and readAllBytes 11772
  • gRPC: Isolate gRPC reflection routing state c16fa9157a
  • gRPC: Resolve deprecations in module helidon-webserver-grpc 11687
  • gRPC: trailers on every gRPC client request 11700
  • HTTP: Add freshness checks for HTTP signatures 7b3d14b8d0
  • HTTP: Add shared HTTP transport observability 12275
  • HTTP: Annotate HTTP encoding APIs with API stability 12380
  • HTTP: Avoid expansion of bit set 11389
  • HTTP: Close HTTP/1.1 connections after Connection: close 12326
  • HTTP: Complete HTTP header and redirect follow-up 12538
  • HTTP: Enforce decoded request entity limits d2e8dd56c9
  • HTTP: Enforce HTTP header size limits consistently f1a376b88c
  • HTTP: Fix Content-Location header constant 11921
  • HTTP: Fix declarative ServerResponse handling 12179
  • HTTP: Fix HTTP parsing and redirect handling 12505
  • HTTP: Fix main build validation failures 12112
  • HTTP: Guard HPACK string length decoding ea9c710cdf
  • HTTP: Handle tokenized HTTP header values and fix HTTP/1 redirect probe framing 11646
  • HTTP: Normalize HTTP diagnostic log newlines 12136
  • HTTP: Optimize header token matching 12294
  • HTTP: Preserve direct handler response metadata 12295
  • HTTP: Re-encoding already encoded content 11658
  • HTTP: Reduce indexed HTTP header allocation 12328
  • HTTP: Reject invalid request content length framing 95de623f89
  • HTTP: Require trusted proxy entry for X-Forwarded URI discovery a7f3d56366
  • HTTP: Resolve deprecations in module helidon-http 11528
  • HTTP: Resolve rebase validation issues 57be94e538
  • HTTP: Sanitize content disposition filenames f43925dd2c
  • HTTP: Support RFC 10008 QUERY method 12518
  • HTTP: Use generic internal error response 1d95b00310
  • HTTP: Use parameter type for declarative query defaults 11590
  • HTTP: Validate HTTP tokens using ASCII grammar 12262
  • HTTP: Validate HTTP/1 response headers by default 567e2ff22a
  • HTTP/2: Avoid redundant HTTP/2 stream setup 12492
  • HTTP/2: Avoid stale HTTP/2 flow control waits 12166
  • HTTP/2: Batch terminal HTTP/2 response writes 12489
  • HTTP/2: Classify HTTP/2 reset write failures as server I/O 12358
  • HTTP/2: Enforce HTTP/2 HEAD and 304 response content semantics 12548
  • HTTP/2: Fail active HTTP/2 streams when the connection closes 12352
  • HTTP/2: Fix HTTP/2 client h2c stalls under load 12007
  • HTTP/2: Fix HTTP/2 client ping handling 11415
  • HTTP/2: Fix HTTP/2 concurrent stream accounting aacbac5cd0
  • HTTP/2: Fix HTTP/2 concurrent stream close accounting 12115
  • HTTP/2: Fix HTTP/2 duplex flow-control liveness 12182
  • HTTP/2: Fix HTTP/2 rejected stream close accounting 12160
  • HTTP/2: Fix HTTP/2 reset stream cleanup race 12143
  • HTTP/2: Fix HTTP/2 Set-Cookie header folding 11554
  • HTTP/2: Fix HTTP/2 split header block serialization 12102
  • HTTP/2: Fix HTTP/2 TLS write race 11666
  • HTTP/2: Ignore in-flight HTTP/2 frames after local stream reset 12481
  • HTTP/2: Make gRPC deframing independent of HTTP/2 DATA boundaries aab097bd1f
  • HTTP/2: Optimize HTTP/2 buffered responses and fix byte ranges 12570
  • HTTP/2: Reject HTTP/2 status changes after requesting output stream 12247
  • HTTP/2: Reject oversized HTTP/2 initial window size 09c2822877
  • HTTP/2: Send GOAWAY for HTTP/2 connection errors 62d8553a3b
  • HTTP/2: Skip unsupported HTTP/2 settings values 12278
  • HTTP/2: Strip HTTP/2 client certificate header from requests 42bb94a98e
  • HTTP/2: Support SSE over HTTP/2 12364
  • JSON-RPC: Replace JSON-P with Helidon JSON in JSON-RPC 12041
  • JSON: Annotate JSON APIs with API stability 12508
  • JSON: Bound JSON BigInteger materialization 517b085431
  • JSON: Double and BigDecimal parsing fixed for streams 11341
  • JSON: Fix JSON stream parser buffer compaction 12159
  • JSON: Fixed Json.Ignore on the record and creator 11784
  • JSON: Helidon JSON modules stability updates 11766
  • JSON: JSON Binding list helper methods 12161
  • JSON: Json Schema changed to use Helidon JSON 11373
  • JSON: JSON-P removed from IDCS, OIDC and JWT 11690
  • JSON: JSON-P replaced in Observe Info 11585
  • JSON: JSON-P replaced in Webserver Observer Log 11610
  • JSON: Limit JSON parser nesting depth 12348
  • JSON: Missing JsonObject.Builder methods added 12158
  • JSON: Optimize JSON media writers for fixed-length entities 12039
  • JSON: Replace JSON-P with Helidon JSON in MongoDB dbclient 12040
  • JSON: Replace JSON-P with Helidon JSON in webserver-observe-metrics 11622
  • JSON: Telemetry tracing test JSON-P removed 11686
  • Logging: Enable logging Javadoc fail on warning 11968
  • Media Support: Enable single-module Javadoc warning checks 11983
  • Media Support: Fixed renamed group id. 11764
  • Media Support: Ignore multipart part Content-Length 7de1830021
  • Media Support: Limit multipart part count b5864d8d40
  • Media Support: Prevent extra data requests on zero-length reads 11434
  • Messaging: Declarative messaging 12304
  • Messaging: Remove messaging module preview flag 12561
  • MetaData: Fix reflection conversion of primitive and array types 12582
  • MetaData: Resolve deprecations in module helidon-metadata 11626
  • Metrics: Allow SE filter to get matching http route from elsewhere and more accurately record request processing time 12331
  • Metrics: Avoid duplicate metrics registry init in declarative apps 11810
  • Metrics: Decouple concurrency limit metrics from socket naming 11867
  • Metrics: Enable metrics Javadoc fail on warning 11989
  • Metrics: Enroll auto HTTP metrics provider filters only once 11625
  • Metrics: Fix FT config bootstrap metrics lookup 12072
  • Metrics: Limit metrics scope to Helidon MP only 12504
  • Metrics: Preserve virtual thread metrics cleanup interrupt 12290
  • Metrics: Remove deprecated GC time type check 12065
  • Metrics: Remove integration for the Prometheus metrics API in 11756
  • Metrics: Resolve metrics API deprecations 12075
  • OpenAPI: Declarative OpenAPI 12073
  • OpenAPI: Protect OpenAPI service routes when authorization is required 12366
  • OTel: Add missing MDC support to OTel config support 11914
  • OTel: Avoid multiple assignments of global OpenTelemetry instance 11576
  • OTel: Correct the calc of OTel http server sem conv; capture end time in whenSent instead of in the filter 12128
  • OTel: Forward port - implement HTTP method name canonicalization required in OTel semantic conventions 12387
  • OTel: Update OpenTelemetry to 1.65 and remove Zipkin exporter 12315
  • port: JSON spec tests and minor fixes 11517
  • Registry: Avoid creating a global service registry during manager shutdown 12337
  • Registry: Avoid service-factory activation and registry-shutdown lock inversion 12529
  • Registry: Fix service registry lookup cache poisoning 12034
  • Registry: Forward-port service registry codegen interface-contract validation 12052
  • Registry: Remove static service lookups from registry-managed services 12335
  • Registry: Resolve service registry deprecations 11631
  • Scheduling: Enable scheduling Javadoc fail on warning 11971
  • Scheduling: Resolve deprecations in helidon-scheduling 11627
  • Security: Avoid CDI tracing lookup during OIDC metadata load 12286
  • Security: Avoid startup failure when JWT provider JWKS is unavailable 12521
  • Security: Encode OIDC logout state 180868328d
  • Security: Encrypt OIDC token cookie by default 81c2f9b9f1
  • Security: Fix HTTP signature review follow-ups a39d220203
  • Security: Fix IDCS mapper token request setup a84686cfb9
  • Security: Fix OIDC secret temp file name c1401092b0
  • Security: Fix post-rebase validation failures 6aa781e8e3
  • Security: Harden OIDC fallback secret file 6de25c4308
  • Security: OIDC cookie compression 12225
  • Security: Preserve OIDC authorization and logout endpoint query parameters 12209
  • Security: Preserve subject types in IDCS role mapping 37bba64351
  • Security: Redact IDCS application access token logs c3829201d7
  • Security: Reject invalid OIDC logout state b96a894919
  • Security: Reject RSA1_5 JWE key management 9f041acaee
  • Security: Reject unknown OIDC tenants before metadata discovery 1281766199
  • Security: Release connection token on setup failure 60aed6eb75
  • Security: Remove HTTP Digest Authentication provider 11716
  • Security: Require JWT claim checks without signatures b7e5c9653b
  • Security: Resolve security deprecations 11628
  • Security: Support custom JWT groups paths 11961
  • Security: Support disabling OIDC redirect attempt param 12009
  • Security: SymmetricCipher builder default iteration increased to 600_000 76a604d707
  • Security: Use constant-time basic auth password comparison 50caa3ee11
  • Security: Validate OIDC post-login redirects 02b5f8fb19
  • Service Registry: Document service static lookup restriction 12322
  • Service Registry: Finish ServiceLoader internalization 11775
  • Service Registry: Fix qualified late-binding lock leak 12024
  • SSE: Fix SSE comment-only events 11974
  • SSE: Fix WsSession.send race 11787
  • SSE: Neutralize line breaks in SSE fields bd1c119ca0
  • SSE: Resolve deprecations in module helidon-webserver-sse 11691
  • SSE: Support pre-compressed static content 12058
  • SSE: Support protocol-owned SSE entity streams 12251
  • Telemetry: Adopt newer semantic conventions, including exposing newly-stable values 12498
  • Telemetry: Allow telemetry to be disabled without startup exception 12493
  • Telemetry: Remove deprecated telemetry tracing host tags 12059
  • Tracing: Change 'requires' to 'requires static' for features API in Jaeger exporter 11395
  • Tracing: Enable tracing Javadoc fail-on-warning 11990
  • Tracing: Remove deprecated tracing baggage APIs 12053
  • Tracing: Remove deprecated tracing compatibility modules 11697
  • Tracing: Remove global tracer ownership 12060
  • Tracing: Wait for all GraphQL tracing spans 12280
  • Validation: Add validation support for MultipleOf constraints 11570
  • Validation: Fix nullable cascading validation 12379
  • WebClient: Clear HTTP/1 read timeout after h2c upgrade 12264
  • WebClient: Add WebClient SNI support 12054
  • WebClient: Avoid unnecessary DNS resolution without proxy 11812
  • WebClient: Backport 4.4.1 fixes from release branch 11829
  • WebClient: Block cross-origin redirect entity replay in WebClient a8aa8aeebc
  • WebClient: Close typed client response when eager entity decoding fails 12023
  • WebClient: Cookies are no longer propagated upon redirect a378444d48
  • WebClient: Delay registry-managed WebClient security resolution 12514
  • WebClient: Deprecate LockingStreamIdSequence constructor 12003
  • WebClient: Enable WebClient Javadoc fail on warning 11985
  • WebClient: Expose active WebClient TCP protocols 12266
  • WebClient: Fix HTTP/1 close-delimited response reuse 12121
  • WebClient: Fix HTTP/1 expect-continue header timeout 12180
  • WebClient: Fix HTTP/1 no-body and close-delimited responses 12081
  • WebClient: Fix UDS client proxy behavior 11935
  • WebClient: Fix Unix address parsing in WebServer and WebClient configuration 11848
  • WebClient: Make LockingStreamIdSequence constructor private 12018
  • WebClient: Normalize WebClient URI schemes before transport selection 0868ce7d38
  • WebClient: Preserve asynchronous trailer failure delivery 88a1e18dc2
  • WebClient: Preserve HTTP/1 response entities with Upgrade headers 12545
  • WebClient: Preserve UDS address across WebClient redirects 11941
  • WebClient: Report the selected WebClient response protocol 12287
  • WebClient: Resolve deprecations in module helidon-webclient-api 11629
  • WebClient: Revalidate cached WebClient protocols 12276
  • WebClient: Share resolved WebClient targets 12301
  • WebClient: Support Alt-Svc in WebClient 12340
  • WebClient: Support Optional declarative client 404 responses 11349
  • WebClient: Use cached shared header constants 12395
  • WebClient: Use request scheme for WebClient security transport 12205
  • WebServer: Accept parsed authority for SNI validation 12250
  • WebServer: Add server Alt-Svc advertisement 12254
  • WebServer: Add Vary for automatic content encoding 12271
  • WebServer: Add WebServer HSTS support 11550
  • WebServer: Add WebServer request-time service locator 12083
  • WebServer: Add WebServer SNI support 12074
  • WebServer: Address error when an unrecognized media type is specified in an OPTIONS request 11311
  • WebServer: BufferDataInputStream must return -1 at EOF, not 0 or throw 11737
  • WebServer: Cache static content metadata 12291
  • WebServer: Clamp static content byte ranges 17e0f295ef
  • WebServer: Contain filesystem static content symlinks 013701b2f2
  • WebServer: Correct several API Javadocs 12472
  • WebServer: Do not send keep-alive in responses 11445
  • WebServer: Drain direct HTTP/1 error responses before close 12525
  • WebServer: Enable WebServer Javadoc fail on warning 11987
  • WebServer: Fall back to NIO for valid static content 9bec8d75a1
  • WebServer: Fix #​11330: use calendar year in access log timestamp 11331
  • WebServer: Fix MadeYouReset reset accounting aed3468de2
  • WebServer: Fix problems enabling request scope in the Webserver 11350
  • WebServer: Fix rapid reset threshold accounting ad4fbbde30
  • WebServer: Fix static content byte ranges 12259
  • WebServer: Fix static content cache accounting 12261
  • WebServer: Fix static content conditional requests 12260
  • WebServer: Fix WebServer idle timeout task lifecycle 11979
  • WebServer: Fix WebServer metrics Javadoc dependencies 12200
  • WebServer: Fix WebServer suspend and resume failure rollback 11950
  • WebServer: Fix WebServer TLS over Unix domain sockets 11930
  • WebServer: Graceful handling of exceptions when writing to response 11660
  • WebServer: Harden filesystem static content access f4012823cf
  • WebServer: Harden HTTP protocol logging fc59103987
  • WebServer: Harden PROXY protocol trusted proxy handling 222abfc80f
  • WebServer: Honor secure handler role hints 1a5ad07240
  • WebServer: Keep selected PROXY handling within the method length limit fc32efb994
  • WebServer: Log expected WebServer connection termination at trace 12542
  • WebServer: Optimize common WebServer hot paths 12537
  • WebServer: Pin static content symlink targets 67de359923
  • WebServer: Propagate WebServer lifecycle failures 11947
  • WebServer: Remove WebServer internal benchmark support 12094
  • WebServer: Reset response entity before error handling 12277
  • WebServer: Resolve deprecations in module helidon-webserver-service-common 11634
  • WebServer: Resolve deprecations in module helidon-webserver 11621
  • WebServer: Resolve deprecations in module helidon-webserver-observe-log 11620
  • WebServer: Resolve deprecations in module helidon-webserver-security 11616
  • WebServer: Resolve deprecations in module helidon-webserver-static-content 11613
  • WebServer: Use custom uncaught exception handlers in WebServer 12030
  • WebServer: WebServer Accepted socket shutdown race 11957
  • WebSocket: Correctly handle default origin logic in Websockets 11439
  • WebSocket: Declarative websocket client without path params generates invalid factory code 11582
  • WebSocket: Fix declarative websocket client primitive text listeners 11587
  • WebSocket: Limit buffered WebSocket message size 7da3f056b8
  • WebSocket: Secure routed WebSocket upgrades 00a9dda230
  • Build: Add Apple Silicon support to ShellCheck script 12234
  • Build: Add jackson and snakeyaml to dependabot 12567
  • Build: CHANGELOG placeholder for 27 12500
  • Build: Clarification of development guidelines 12578
  • Build: dependency check updates 11980
  • Build: Enable Javadoc fail-on-warning for health modules 11966
  • Build: Fix Maven Invoker split repository handling 12516
  • Build: Fix SCM connection urls in parent pom 12562
  • Build: Helidon core 27 11315
  • Build: Java 26 11345
  • Build: Java features - unnamed variable 11357
  • Build: Restore CI build-cache fast-forwarding 12256
  • Build: Switch to new examples branch. 11338
  • Build: Update development guidelines 12320
  • Build: Update for examples simplification 12484
  • Build: Update release smoketest to use CLI and only SE archetypes 12535
  • Build: Update third party license attributions 12585
  • Build: Upgrade to Java 27 12577
  • Build: Use deployment id for accessing staged artifacts from sonatype 11630
  • Dependencies: dependency cleanup 12093
  • Dependencies: log4j 2.25.5 12173
  • Dependencies: pom cleanup 12327
  • Dependencies: Remove dependency management of netty 11523
  • Dependencies: Remove dependencyManagement for jaxb artifacts 12332
  • Dependencies: Upgrade ASM to 9.10.1 12539
  • Dependencies: Upgrade Checkstyle to support flexible constructor bodies 12491
  • Dependencies: Upgrade from Prometheus simpleclient to Java client 12494
  • Dependencies: Upgrade gson to 2.13.2 11520
  • Dependencies: Upgrade handlebars to 4.5.1 11925
  • Dependencies: Upgrade Jackson to 2.21.6 12309
  • Dependencies: Upgrade Jackson, Parsson and Handlebars 12167
  • Dependencies: Upgrade JMH to 1.37 12486
  • Dependencies: Upgrade log4j to 2.25.4 11817
  • Dependencies: upgrade maven api to 3.9.15 11731
  • Dependencies: Upgrade postgres driver to 42.7.13 12201
  • Dependencies: upgrade postgres jdbc driver to 42.7.11 11851
  • Dependencies: Upgrade Protobuf to 4.36.0 12393
  • Dependencies: upgrade protobuf to 4.36.0 and micrometer to 1.17.1 12378
  • Dependencies: upgrade snakeyaml to 2.7 and mongodb driver to 5.11.1 12584
  • Docs: 27 upgrade guide 12556
  • Docs: Add documentation for declarative Health. 11354
  • Docs: APM service integration 11694
  • Docs: Change from using legacy maven archetype to helidon cli 12550
  • Docs: Complete the Helidon 27 application migration guide 12576
  • Docs: Convert AsciiDoc documentation to Markdown 12389
  • Docs: Document max-tcp-connections admission semantics [11945](https://redirect.github.com/helidon-i

❗ Important

✂ PR body was truncated to here.


Configuration

📅 Schedule: (UTC)

  • Branch creation
    • At any time (no schedule defined)
  • Automerge
    • At any time (no schedule defined)

🚦 Automerge: Disabled by config. Please merge this manually once you are satisfied.

♻ Rebasing: Whenever PR becomes conflicted, or you tick the rebase/retry checkbox.

🔕 Ignore: Close this PR and you won't be reminded about this update again.


  • If you want to rebase/retry this PR, check this box

This PR was generated by Mend Renovate. View the repository job log.

@renovate
renovate Bot force-pushed the renovate/major-helidon branch from 541695e to e790b4c Compare September 24, 2026 22:29
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

0 participants