Skip to content

chore: bump io.github.classgraph:classgraph from 4.8.196 to 4.8.197 - #642

Merged
bwRavencl merged 1 commit into
masterfrom
dependabot/gradle/io.github.classgraph-classgraph-4.8.197
Oct 7, 2026
Merged

bwRavencl merged 1 commit into
masterfrom
dependabot/gradle/io.github.classgraph-classgraph-4.8.197

Conversation

@dependabot

@dependabot dependabot Bot commented on behalf of github Oct 7, 2026

Copy link
Copy Markdown
Contributor

Bumps io.github.classgraph:classgraph from 4.8.196 to 4.8.197.

Release notes

Sourced from io.github.classgraph:classgraph's releases.

ClassGraph 4.8.197

ClassGraph 5.0.0 is coming shortly, and requires JDK 17 or newer. 4.8.197 is a bugfix release on the 4.x maintenance branch. As before, most of the bugs listed here were found by Claude through careful code analysis, and were fixed on the v5 branch and backported to v4.

Behavior changes

  • A wildcard classpath entry such as lib/* now adds only jarfiles, as the java launcher does. It added every entry of the directory, including subdirectories, zipfiles and other files. The launcher decides by name alone, adding the entries whose names end in .jar or .JAR, and ClassGraph now applies the same rule.

  • Methods that require a scan option now throw IllegalArgumentException whenever that option was not enabled, even when there is nothing to test. Before, they returned an empty result when there was nothing to test (a class with no methods or fields, or a method with no parameters), and threw only otherwise. This applies to ClassInfo#getMethodInfoWithAnnotation, getDeclaredMethodInfoWithAnnotation, getFieldInfoWithAnnotation and getDeclaredFieldInfoWithAnnotation (which require enableAnnotationInfo()), MethodInfo#hasParameterAnnotation (likewise), and ScanResult#getClassDependencyMap and getReverseClassDependencyMap (which require enableInterClassDependencies()).

Bug fixes: classpath and URLs

  • A URL with a custom scheme and an empty authority lost the slash that begins its path, so custom:///a/b became custom://a/b, which names a as the host. On Windows, custom:///C:/a/b also lost the slash before the drive letter, which made C: the host.

  • A classpath element with a custom URL scheme was reported under a file: URI, so custom:/dir/x.jar was reported as file:custom%3a/dir/x.jar. It is now reported under its own scheme.

  • The classpath entry * found nothing when the user.dir property could not be read (on JDK versions before 25). It now lists the current directory.

  • The extra classpath entries of Uno-Jar and One-Jar, which are separated by |, were each split again at the platform's path separator, so an entry whose name contained that separator was lost.

  • An automatic module name is no longer derived from a jarfile name that the JDK would reject: one with an empty part, a part that starts with a digit, or a part that is a Java keyword or literal.

Bug fixes: reading streams

InputStream#read(byte[], int, int) may return 0 without being at the end of the stream, and two readers mishandled this:

  • A classfile read from such a stream failed with "Tried to read past the end of the classfile".
  • Copying such a stream to a temporary file looped forever if the stream returned 0 at its end.

Bug fixes: the class graph

  • getFieldInfo() and the field override order now search a class, then its direct superinterfaces, then its superclass, as the JVM resolves fields (JVMS 5.4.3.2).

  • MethodInfo#isDefault() now reports only public, non-abstract, non-static interface methods.

  • equalsIgnoringTypeParams() now compares the suffixes of a class reference type signature, and ignores type annotations on type variables, as its documentation says.

  • AnnotationInfoList#getRepeatable() now keeps the record of which annotations are directly present.

Documentation

Javadoc and comment corrections, among them: getClasspath() now says that a : inside a file path is written as \:, and Resource#getLastModified() now says that zip entry times have a resolution of two seconds.

Commits
  • ff37f9a [maven-release-plugin] prepare release classgraph-4.8.197
  • a513553 Keep the slash before a drive letter in a custom-scheme URL on Windows
  • a57323e Find the jarfiles in the current directory when user.dir cannot be read; keep...
  • 0d3926f Keep reading a stream that returns zero bytes from a bulk read
  • 0a133b9 Keep a custom URL scheme in resolved paths and reported URIs
  • cd24449 Backport v5 correctness fixes and comment corrections
  • e484e13 Add only jarfiles for a wildcard classpath entry, as the java launcher does
  • b511a2e [maven-release-plugin] prepare for next development iteration
  • See full diff in compare view

Most Recent Ignore Conditions Applied to This Pull Request
Dependency Name Ignore Conditions
io.github.classgraph:classgraph [>= 4.8.181.a, < 4.8.182]

Dependabot compatibility score

Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting @dependabot rebase.


Dependabot commands and options

You can trigger Dependabot actions by commenting on this PR:

  • @dependabot rebase will rebase this PR
  • @dependabot recreate will recreate this PR, overwriting any edits that have been made to it
  • @dependabot show <dependency name> ignore conditions will show all of the ignore conditions of the specified dependency
  • @dependabot ignore this major version will close this PR and stop Dependabot creating any more for this major version (unless you reopen the PR or upgrade to it yourself)
  • @dependabot ignore this minor version will close this PR and stop Dependabot creating any more for this minor version (unless you reopen the PR or upgrade to it yourself)
  • @dependabot ignore this dependency will close this PR and stop Dependabot creating any more for this dependency (unless you reopen the PR or upgrade to it yourself)

Bumps [io.github.classgraph:classgraph](https://github.com/classgraph/classgraph) from 4.8.196 to 4.8.197.
- [Release notes](https://github.com/classgraph/classgraph/releases)
- [Commits](classgraph/classgraph@classgraph-4.8.196...classgraph-4.8.197)

---
updated-dependencies:
- dependency-name: io.github.classgraph:classgraph
  dependency-version: 4.8.197
  dependency-type: direct:production
  update-type: version-update:semver-patch
...

Signed-off-by: dependabot[bot] <support@github.com>
@dependabot dependabot Bot added dependencies Pull requests that update a dependency file java Pull requests that update Java code labels Oct 7, 2026
@bwRavencl
bwRavencl merged commit e46e06b into master Oct 7, 2026
1 check passed
@dependabot
dependabot Bot deleted the dependabot/gradle/io.github.classgraph-classgraph-4.8.197 branch October 7, 2026 13:18
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

dependencies Pull requests that update a dependency file java Pull requests that update Java code

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant