)]}'
{
  "log": [
    {
      "commit": "44f7aa35a6b90ac7d39ef0e68dad706561235941",
      "tree": "a6df1277ad22b980fc543f2579fa37953e213ebc",
      "parents": [
        "378e5e25005f580e23692d94b263277b05404ab1"
      ],
      "author": {
        "name": "Ismaël Mejía",
        "email": "iemejia@gmail.com",
        "time": "Sun Jul 26 19:08:53 2026 +0200"
      },
      "committer": {
        "name": "GitHub",
        "email": "noreply@github.com",
        "time": "Sun Jul 26 19:08:53 2026 +0200"
      },
      "message": "AVRO-4313: [java] Tighten javaAnnotation string-literal validation in SpecificCompiler (#3892)\n\n* AVRO-4313: [java] Tighten javaAnnotation string-literal validation in SpecificCompiler\n\nThe string-literal grammar used to validate javaAnnotation values accepted\nan unescaped quote inside the literal body, letting a single literal span\npast its intended closing quote and absorb surrounding tokens. Constrain the\nbody to recognized escape sequences or characters that are not a quote,\nbackslash, or line terminator, and add a regression test.\n\n* AVRO-4313: Exclude all line terminators from annotation string literals\n\nAlso reject NEL, LS and PS in addition to CR and LF so an annotation value\ncannot span multiple lines in the generated source.\n\n* AVRO-4313: Make injection regression test robust to multiple outputs\n\nAssert the injection payload is absent from every generated file and the\nvalid annotation is emitted in at least one, rather than requiring it in\neach output file."
    },
    {
      "commit": "378e5e25005f580e23692d94b263277b05404ab1",
      "tree": "eccb91282faaeb4facb096b05bc42d6b19681258",
      "parents": [
        "2c5dec675a5a335950a175f331f9b6c254b8d128"
      ],
      "author": {
        "name": "dependabot[bot]",
        "email": "49699333+dependabot[bot]@users.noreply.github.com",
        "time": "Sun Jul 26 18:55:23 2026 +0200"
      },
      "committer": {
        "name": "GitHub",
        "email": "noreply@github.com",
        "time": "Sun Jul 26 18:55:23 2026 +0200"
      },
      "message": "Bump autoprefixer from 10.5.2 to 10.5.4 in /doc (#3884)\n\nBumps [autoprefixer](https://github.com/postcss/autoprefixer) from 10.5.2 to 10.5.4.\n- [Release notes](https://github.com/postcss/autoprefixer/releases)\n- [Changelog](https://github.com/postcss/autoprefixer/blob/main/CHANGELOG.md)\n- [Commits](https://github.com/postcss/autoprefixer/compare/10.5.2...10.5.4)\n\n---\nupdated-dependencies:\n- dependency-name: autoprefixer\n  dependency-version: 10.5.4\n  dependency-type: direct:development\n  update-type: version-update:semver-patch\n...\n\nSigned-off-by: dependabot[bot] \u003csupport@github.com\u003e\nCo-authored-by: dependabot[bot] \u003c49699333+dependabot[bot]@users.noreply.github.com\u003e"
    },
    {
      "commit": "2c5dec675a5a335950a175f331f9b6c254b8d128",
      "tree": "62dfd57c192060a729620d904adc7ea7cf543a02",
      "parents": [
        "8a61917e4f51c0dfe7586298d05e405714c13132"
      ],
      "author": {
        "name": "dependabot[bot]",
        "email": "49699333+dependabot[bot]@users.noreply.github.com",
        "time": "Sun Jul 26 18:48:50 2026 +0200"
      },
      "committer": {
        "name": "GitHub",
        "email": "noreply@github.com",
        "time": "Sun Jul 26 18:48:50 2026 +0200"
      },
      "message": "Bump System.CodeDom from 10.0.9 to 10.0.10 (#3888)\n\n---\nupdated-dependencies:\n- dependency-name: System.CodeDom\n  dependency-version: 10.0.10\n  dependency-type: direct:production\n  update-type: version-update:semver-patch\n...\n\nSigned-off-by: dependabot[bot] \u003csupport@github.com\u003e\nCo-authored-by: dependabot[bot] \u003c49699333+dependabot[bot]@users.noreply.github.com\u003e"
    },
    {
      "commit": "8a61917e4f51c0dfe7586298d05e405714c13132",
      "tree": "1c371c6d8d0633eb4797a8b19fe7bc312c2cec16",
      "parents": [
        "587cfc79d4115a16d64121cd63a9318ac3e14ce8"
      ],
      "author": {
        "name": "dependabot[bot]",
        "email": "49699333+dependabot[bot]@users.noreply.github.com",
        "time": "Sun Jul 26 18:48:38 2026 +0200"
      },
      "committer": {
        "name": "GitHub",
        "email": "noreply@github.com",
        "time": "Sun Jul 26 18:48:38 2026 +0200"
      },
      "message": "Bump Microsoft.Build.Framework and Microsoft.Build.Utilities.Core (#3887)\n\nBumps Microsoft.Build.Framework from 18.7.1 to 18.8.2\nBumps Microsoft.Build.Utilities.Core from 18.7.1 to 18.8.2\n\n---\nupdated-dependencies:\n- dependency-name: Microsoft.Build.Framework\n  dependency-version: 18.8.2\n  dependency-type: direct:production\n  update-type: version-update:semver-minor\n- dependency-name: Microsoft.Build.Utilities.Core\n  dependency-version: 18.8.2\n  dependency-type: direct:production\n  update-type: version-update:semver-minor\n...\n\nSigned-off-by: dependabot[bot] \u003csupport@github.com\u003e\nCo-authored-by: dependabot[bot] \u003c49699333+dependabot[bot]@users.noreply.github.com\u003e"
    },
    {
      "commit": "587cfc79d4115a16d64121cd63a9318ac3e14ce8",
      "tree": "5be76111819d13e3454d9709801b518b1ffd5426",
      "parents": [
        "a78a6ca11ba824221d720aebcdc43470f60cc646"
      ],
      "author": {
        "name": "dependabot[bot]",
        "email": "49699333+dependabot[bot]@users.noreply.github.com",
        "time": "Sun Jul 26 18:48:21 2026 +0200"
      },
      "committer": {
        "name": "GitHub",
        "email": "noreply@github.com",
        "time": "Sun Jul 26 18:48:21 2026 +0200"
      },
      "message": "Update mypy requirement from \u003c2.3.0 to \u003c2.4.0 in /lang/py (#3885)\n\nUpdates the requirements on [mypy](https://github.com/python/mypy) to permit the latest version.\n- [Changelog](https://github.com/python/mypy/blob/master/CHANGELOG.md)\n- [Commits](https://github.com/python/mypy/compare/v0.1.0...v2.3.0)\n\n---\nupdated-dependencies:\n- dependency-name: mypy\n  dependency-version: 2.3.0\n  dependency-type: direct:development\n...\n\nSigned-off-by: dependabot[bot] \u003csupport@github.com\u003e\nCo-authored-by: dependabot[bot] \u003c49699333+dependabot[bot]@users.noreply.github.com\u003e"
    },
    {
      "commit": "a78a6ca11ba824221d720aebcdc43470f60cc646",
      "tree": "c3876f2a74945adb13ef61af9331d259d891c456",
      "parents": [
        "d5c3aa62cb6122adaf9b762ddcd57995392fab52"
      ],
      "author": {
        "name": "dependabot[bot]",
        "email": "49699333+dependabot[bot]@users.noreply.github.com",
        "time": "Sun Jul 26 18:47:38 2026 +0200"
      },
      "committer": {
        "name": "GitHub",
        "email": "noreply@github.com",
        "time": "Sun Jul 26 18:47:38 2026 +0200"
      },
      "message": "Bump actions/setup-node from 6 to 7 (#3883)\n\nBumps [actions/setup-node](https://github.com/actions/setup-node) from 6 to 7.\n- [Release notes](https://github.com/actions/setup-node/releases)\n- [Commits](https://github.com/actions/setup-node/compare/v6...v7)\n\n---\nupdated-dependencies:\n- dependency-name: actions/setup-node\n  dependency-version: \u00277\u0027\n  dependency-type: direct:production\n  update-type: version-update:semver-major\n...\n\nSigned-off-by: dependabot[bot] \u003csupport@github.com\u003e\nCo-authored-by: dependabot[bot] \u003c49699333+dependabot[bot]@users.noreply.github.com\u003e"
    },
    {
      "commit": "d5c3aa62cb6122adaf9b762ddcd57995392fab52",
      "tree": "05aedda0b6e4a82f50707a89aa51f6b59763e6b5",
      "parents": [
        "2a9b0feaab58cdaa6b8046c95127341105f60fad"
      ],
      "author": {
        "name": "dependabot[bot]",
        "email": "49699333+dependabot[bot]@users.noreply.github.com",
        "time": "Sun Jul 26 18:47:34 2026 +0200"
      },
      "committer": {
        "name": "GitHub",
        "email": "noreply@github.com",
        "time": "Sun Jul 26 18:47:34 2026 +0200"
      },
      "message": "Bump postcss from 8.5.17 to 8.5.20 in /doc (#3882)\n\nBumps [postcss](https://github.com/postcss/postcss) from 8.5.17 to 8.5.20.\n- [Release notes](https://github.com/postcss/postcss/releases)\n- [Changelog](https://github.com/postcss/postcss/blob/main/CHANGELOG.md)\n- [Commits](https://github.com/postcss/postcss/compare/8.5.17...8.5.20)\n\n---\nupdated-dependencies:\n- dependency-name: postcss\n  dependency-version: 8.5.20\n  dependency-type: direct:development\n  update-type: version-update:semver-patch\n...\n\nSigned-off-by: dependabot[bot] \u003csupport@github.com\u003e\nCo-authored-by: dependabot[bot] \u003c49699333+dependabot[bot]@users.noreply.github.com\u003e"
    },
    {
      "commit": "2a9b0feaab58cdaa6b8046c95127341105f60fad",
      "tree": "95cb76af413e84d7956eaa9ee92bcaa0f79aad53",
      "parents": [
        "07ac413eee65f493db899e0cb3caf67eea99006b"
      ],
      "author": {
        "name": "dependabot[bot]",
        "email": "49699333+dependabot[bot]@users.noreply.github.com",
        "time": "Sun Jul 26 18:45:57 2026 +0200"
      },
      "committer": {
        "name": "GitHub",
        "email": "noreply@github.com",
        "time": "Sun Jul 26 18:45:57 2026 +0200"
      },
      "message": "Bump actions/setup-dotnet from 5 to 6 (#3881)\n\nBumps [actions/setup-dotnet](https://github.com/actions/setup-dotnet) from 5 to 6.\n- [Release notes](https://github.com/actions/setup-dotnet/releases)\n- [Commits](https://github.com/actions/setup-dotnet/compare/v5...v6)\n\n---\nupdated-dependencies:\n- dependency-name: actions/setup-dotnet\n  dependency-version: \u00276\u0027\n  dependency-type: direct:production\n  update-type: version-update:semver-major\n...\n\nSigned-off-by: dependabot[bot] \u003csupport@github.com\u003e\nCo-authored-by: dependabot[bot] \u003c49699333+dependabot[bot]@users.noreply.github.com\u003e"
    },
    {
      "commit": "07ac413eee65f493db899e0cb3caf67eea99006b",
      "tree": "ff2317526ebfb88e365474f1cccb99581b071a99",
      "parents": [
        "787adb119c707815e8c6e75289a40a8ec989bc65"
      ],
      "author": {
        "name": "Ryan Skraba",
        "email": "ryan@skraba.com",
        "time": "Sun Jul 26 18:44:56 2026 +0200"
      },
      "committer": {
        "name": "GitHub",
        "email": "noreply@github.com",
        "time": "Sun Jul 26 18:44:56 2026 +0200"
      },
      "message": "AVRO-4309: [Python][Build] Add uvx to path explicitly (#3879)"
    },
    {
      "commit": "787adb119c707815e8c6e75289a40a8ec989bc65",
      "tree": "df0be21ec1fa48baf6912f32e8b63972ae3d06d7",
      "parents": [
        "eab0e48bb8b7b21d78b0aa2121fe107600e10af6"
      ],
      "author": {
        "name": "Ismaël Mejía",
        "email": "iemejia@gmail.com",
        "time": "Wed Jul 22 18:13:45 2026 +0200"
      },
      "committer": {
        "name": "GitHub",
        "email": "noreply@github.com",
        "time": "Wed Jul 22 18:13:45 2026 +0200"
      },
      "message": "AVRO-4314: [csharp] Validate names against the Avro name grammar (#3895)\n\n* AVRO-4314: [csharp] Validate names against the Avro name grammar\n\nRecord/fixed/enum names, record field names and protocol message names\nwere accepted verbatim when parsing, unlike enum symbols which were\nalready validated. Because the code generator splices some of these\nvalues directly into generated C# source (for example protocol message\nnames into a case label and field names into Get/Put switch bodies), an\nout-of-spec name produced malformed or unexpected generated code.\n\nAdd a shared, Unicode-aware name validator (first character a letter or\n\u0027_\u0027, remaining characters letters, digits or \u0027_\u0027) and apply it to\nschema names, field names and message names during parsing. The rule is\nUnicode-aware to preserve the existing support for non-ASCII names, and\nnamespaces are intentionally not validated because the code generator\u0027s\nnamespace-mapping feature rewrites them to C#-specific values (such as\n\"@return\") and re-parses the schema. Add negative tests for invalid\nfield, record and message names.\n\n* AVRO-4314: [csharp] Validate field aliases and sanitize name errors\n\nAddress review feedback:\n- Validate record field aliases with the same rule as field names, since\n  aliases participate in schema resolution and are names per the Avro\n  grammar. Previously they were accepted verbatim.\n- Escape control characters (and quote the value) when embedding an\n  invalid name in the SchemaParseException message, so a crafted name\n  containing newlines or other control characters cannot produce\n  multi-line or ambiguous error output.\n\nAdd a negative test for an invalid field alias.\n\n* AVRO-4314: [csharp] Handle supplementary-plane characters in names\n\nAddress review feedback: ValidateName inspected individual UTF-16 code\nunits, which rejected valid supplementary-plane letters and digits that\nare encoded as surrogate pairs. Iterate by Unicode scalar value using\nthe char.IsLetter(string, int) / char.IsLetterOrDigit(string, int)\noverloads and advance past surrogate pairs. Add a test that a name\ncontaining a supplementary-plane letter (U+20000) is accepted."
    },
    {
      "commit": "eab0e48bb8b7b21d78b0aa2121fe107600e10af6",
      "tree": "a619cd688a0909c6bab429731e52e21c1843b104",
      "parents": [
        "61270d45bf53d2b05f88d8b02c503e868e23fcaf"
      ],
      "author": {
        "name": "Ismaël Mejía",
        "email": "iemejia@gmail.com",
        "time": "Tue Jul 21 14:51:29 2026 +0200"
      },
      "committer": {
        "name": "GitHub",
        "email": "noreply@github.com",
        "time": "Tue Jul 21 14:51:29 2026 +0200"
      },
      "message": "AVRO-4308: [python] Fix interop build failure from setuptools package discovery (#3894)\n\nThe local Docker interop build failed with \"Multiple top-level packages\ndiscovered in a flat-layout: [\u0027avro\u0027, \u0027userlogs\u0027]\". The Hadoop tether\ntests leave a userlogs/ directory next to the avro/ package, which breaks\nsetuptools automatic flat-layout package discovery.\n\nExplicitly scope package discovery to avro* so stray directories such as\nuserlogs/ are ignored."
    },
    {
      "commit": "61270d45bf53d2b05f88d8b02c503e868e23fcaf",
      "tree": "ef8b68c350c4110b6f76b6d67094be99dfa9a5fc",
      "parents": [
        "f3bb10eaea1f03eb17893bc779eb26213da8177c"
      ],
      "author": {
        "name": "Ismaël Mejía",
        "email": "iemejia@gmail.com",
        "time": "Sun Jul 19 15:30:34 2026 +0200"
      },
      "committer": {
        "name": "GitHub",
        "email": "noreply@github.com",
        "time": "Sun Jul 19 15:30:34 2026 +0200"
      },
      "message": "AVRO-4300: [java] Bound array/map allocation and skipping for zero-byte elements and on the fast reader path (#3865)\n\n* AVRO-4300: [java] Bound zero-byte array element allocation\n\nAn array whose element schema encodes to zero bytes (null, a zero-length\nfixed, or a record with only zero-byte fields) consumes no input per element,\nso the number of elements a block declares cannot be bounded by the bytes\nremaining in the stream. ensureAvailableCollectionBytes therefore skips the\ncheck for such elements, and the collection-length cap is Integer.MAX_VALUE-8\n(a VM array-size ceiling, not a memory budget). A tiny payload declaring a huge\nblock count of such elements (e.g. {\"type\":\"array\",\"items\":\"null\"} with a\ncount of 200,000,000) drives an unbounded backing-array allocation and exhausts\nthe heap. This affects both the classic GenericDatumReader.readArray path and\nthe default fast-reader path (FastReaderBuilder), which had no collection guard\nat all.\n\nAdd SystemLimitException.checkMaxCollectionAllocation, a heap-aware cumulative\ncap (default: maxMemory()/4/8 elements, overridable via the\norg.apache.avro.limits.collectionItems.maxAllocation system property, mirroring\nthe existing decompression limit). Enforce it before allocating in both reader\npaths, keyed on GenericDatumReader.isZeroByteSchema so only the unbounded\nzero-byte case is affected; all other element types remain bounded by\nensureAvailableCollectionBytes and are unchanged. Maps are already bounded\nbecause each entry carries a string key of at least one byte.\n\nAssisted-by: GitHub Copilot:claude-opus-4.8\n\n* AVRO-4300: [java] Apply the available-bytes check on the fast reader path\n\nThe fast reader (FastReaderBuilder, the default decode path) never received the\nAVRO-4241 bytes-remaining guard: that change only touched the classic\nGenericDatumReader. As a result an array of non-zero-byte elements with a huge\ndeclared block count and no data (e.g. array\u003clong\u003e/array\u003cint\u003e with a count of\n200,000,000) still pre-allocated new GenericData.Array\u003c\u003e((int) count) on the\ndefault path and exhausted the heap.\n\nExpose GenericDatumReader.ensureAvailableCollectionBytes and apply it, together\nwith the zero-byte allocation cap, before allocating each array block in\nFastReaderBuilder, so the fast and classic readers enforce identical guards.\nMaps were already safe on both paths (each entry carries a \u003e\u003d1-byte key).\n\nVerified with a matrix of array\u003cnull|long|int\u003e and map\u003cnull|long\u003e at a huge\ncount under -Xmx256m: every combination is now rejected (SystemLimitException\nfor zero-byte elements, EOFException otherwise) on both reader paths instead of\nOOM.\n\nAssisted-by: GitHub Copilot:claude-opus-4.8\n\n* AVRO-4300: [java] Cover all collection/reader combinations in tests\n\nAdd a matrix test asserting every collection kind is rejected (never OOM) with\na huge block count and no data, on both the fast (default) and classic reader:\narray\u003cnull\u003e via the heap-aware allocation cap (SystemLimitException) and\narray\u003clong\u003e, array\u003cint\u003e, map\u003cnull\u003e, map\u003clong\u003e via the bytes-remaining check\n(EOFException) -- the full 5x2 set of combinations. Keep a cumulative\nmulti-block null test and a positive within-limit decode test on both readers.\n\nAssisted-by: GitHub Copilot:claude-opus-4.8\n\n* AVRO-4300: [java] Test negative block count is bounded on both readers\n\nThe C and Python collection-limit tests cover a negative block count (abs(count)\nzero-byte elements preceded by a block byte-size); the Java tests did not. The\ndecoder normalizes the negative count to a positive one, which must still be\nbounded by the heap-aware allocation cap. Add a test asserting this on both the\nfast and classic reader paths.\n\nAssisted-by: GitHub Copilot:claude-opus-4.8\n\n* AVRO-4300: [java] Test Long.MIN_VALUE block count is handled safely\n\nMirror the C SDK\u0027s INT64_MIN edge case. Long.MIN_VALUE as a block count is the\npathological overflow: negating it overflows back to a negative value. Java\u0027s\ndecoder normalizes this to an empty collection (no allocation) rather than\nrejecting it as the C SDK does, which is equally non-exploitable. Add a test\nasserting the safe, allocation-free result on both the fast and classic reader\npaths.\n\nAssisted-by: GitHub Copilot:claude-opus-4.8\n\n* AVRO-4300: [java] Bound the array/map skip path\n\nThe skip path was unbounded: BinaryDecoder.skipArray()/skipMap() returned\ndoSkipItems() without calling checkMaxCollectionLength, and\nGenericDatumReader.skip() looped over the returned count. Skipping a huge block\nof zero-byte elements (e.g. a writer array\u003cnull\u003e field absent from the reader\nschema, skipped during projection) could therefore loop unboundedly -- a CPU\nexhaustion even though skipping reads and allocates nothing.\n\nTwo complementary bounds:\n - BinaryDecoder.skipArray()/skipMap() now apply the structural collection cap\n   (checkMaxCollectionLength), mirroring readArrayStart()/readMapStart() and\n   covering the resolving-decoder projection skip path on both reader types.\n - GenericDatumReader.skip() additionally bounds the cumulative count, using the\n   heap-aware allocation cap for zero-byte element arrays and the structural cap\n   otherwise, matching the read path and the other language SDKs.\n\nAssisted-by: GitHub Copilot:claude-opus-4.8\n\n* AVRO-4300: [java] Fix limit Javadoc markup; clamp allocation cap to VM limit\n\nAddresses review feedback:\n - Fix the malformed \u003cli\u003e markup in the limit-properties list (each item closed\n   \u003c/li\u003e prematurely after the \u003ctt\u003e tag) and correct the bytes property name\n   (org.apache.avro.limits.bytes.maxLength) so the Javadoc renders correctly.\n - Clamp maxCollectionAllocation to MAX_ARRAY_VM_LIMIT when refreshing limits, so\n   a configured (or large-heap-derived) zero-byte allocation cap stays consistent\n   with the other collection caps and cannot exceed the VM array ceiling.\n\nAssisted-by: GitHub Copilot:claude-opus-4.8\n\n* AVRO-4300: [java] Fix limit Javadoc grammar; make heap-cap test deterministic\n\nAddresses review feedback:\n - Javadoc: \"read at once single sequence\" -\u003e \"read in a single sequence\".\n - testCheckMaxCollectionAllocation asserts with MAX_ARRAY_VM_LIMIT + 1 instead\n   of Integer.MAX_VALUE - 8. Since the default allocation cap is derived from the\n   heap and then clamped to MAX_ARRAY_VM_LIMIT, a value equal to that limit may\n   not exceed the computed default on a very large heap; +1 guarantees it does,\n   keeping the test deterministic across environments.\n\nAssisted-by: GitHub Copilot:claude-opus-4.8\n\n* AVRO-4300: [java] Reword zero-byte Javadoc; tighten skip test assertions\n\nAddresses review feedback:\n - Javadoc: \"a self-referencing record\" is not inherently zero-byte (the code\n   only computes a 0-byte minimum for some recursive schemas to break recursion).\n   Reword the three occurrences to describe actual zero-byte encodings: null, a\n   zero-length fixed, or a record whose fields all encode to zero bytes.\n - skipMapRejectsHugeCount now asserts UnsupportedOperationException (a count of\n   Integer.MAX_VALUE deterministically hits the VM structural-limit path), and\n   resolvingSkipOfHugeNullArrayFieldIsBounded asserts SystemLimitException, so the\n   tests pin the intended exception rather than a generic RuntimeException.\n\nAssisted-by: GitHub Copilot:claude-opus-4.8\n\n* AVRO-4300: [java] Apply spotless formatting to reworded Javadoc\n\nThe zero-byte Javadoc rewording did not match the Eclipse formatter\u0027s\nline-wrapping, failing the spotless check. Reflowed via `mvn spotless:apply`.\n\nAssisted-by: GitHub Copilot:claude-opus-4.8\n\n* AVRO-4300: [java] Clarify zero-byte comments to match the actual predicate\n\nAddresses review feedback: the \"encodes to zero bytes\" wording in\nGenericDatumReader (the array cap comment and isZeroByteSchema Javadoc) and\nFastReaderBuilder is imprecise. The guard is minBytesPerElement(schema) \u003d\u003d 0,\nwhich is also true for recursive schemas whose cycle is broken by returning a 0\nminimum. Reword to describe the \"minimum encoded size is zero\" predicate so the\ndocs match the actual condition under which the heap-aware cap applies.\n\nAssisted-by: GitHub Copilot:claude-opus-4.8\n\n* AVRO-4300: [java] Reject Long.MIN_VALUE block count as malformed\n\nAddresses review feedback: doReadItemCount() negates a negative block count, but\nLong.MIN_VALUE negates back to Long.MIN_VALUE (still negative). The single-arg\ncheckMaxCollectionLength does not reject negatives, so it was truncated via\n(int) cast to 0, silently ending the collection without consuming the\nend-of-array/map marker and desynchronizing decoding of subsequent fields.\n\nReject Long.MIN_VALUE outright as malformed, matching the C SDK, instead of\nnormalizing to an empty collection. Update the test to assert the rejection.\n\nAssisted-by: GitHub Copilot:claude-opus-4.8\n\n* AVRO-4300: [java] Clamp collection preallocation from declared block count\n\nThe array/map readers passed the declared block count straight to newArray/\nnewMap as the initial capacity. On a stream source the bytes-available guard is\nskipped (BinaryDecoder.remainingBytes() returns -1 for sources other than\nByteArrayInputStream/ByteBufferInputStream), so a large declared count reaches\nthe allocation path directly and drives a huge up-front allocation (e.g.\nnew Object[count]) before a single element is read.\n\nClamp the initial capacity to a modest bound (MAX_COLLECTION_PREALLOC) via\ninitialCollectionCapacity(); the backing array/map still grows on demand as\nelements are decoded, so a truncated or hostile stream now fails with\nEOFException after a bounded allocation instead of attempting to preallocate\nhundreds of millions of slots. Applies to both the classic and fast readers.\n\nAssisted-by: GitHub Copilot:claude-opus-4.8\n\n* AVRO-4300: [java] Reject out-of-range union and enum indices with AvroTypeException\n\nThe union branch index and enum symbol index were used to index the branch/\nsymbol tables without an explicit range check on several paths, surfacing a\nmalformed index as a generic IndexOutOfBoundsException instead of a clear\nAvro-specific error:\n\n- Union: Symbol.Alternative.getSymbol (used by both the validating and resolving\n  decoders, and therefore by GenericDatumReader and the fast reader) indexed\n  symbols[] directly. Add a [0, size) check throwing AvroTypeException.\n- Enum: ResolvingDecoder.readEnum returned the raw index in the no-adjustments\n  case and indexed the adjustment table otherwise, both without validation\n  (ValidatingDecoder.readEnum already checked). Add the range checks.\n- The fast reader reads from a plain decoder (resolution is pre-baked), so its\n  union and enum readers need their own [0, length) checks.\n\nAdds tests covering negative and too-large union and enum indices on both the\nclassic and fast reader paths.\n\nAssisted-by: GitHub Copilot:claude-opus-4.8\n\n* AVRO-4300: [java] Reword remaining \"zero-byte\" docs to the actual predicate\n\nThe maxAllocation limit is applied when a schema\u0027s minimum encoded size is zero\n(GenericDatumReader.isZeroByteSchema, i.e. minBytesPerElement \u003d\u003d 0), which also\ncovers recursive schemas whose cycle is conservatively broken with a 0 minimum.\nReword the remaining \"encodes to zero bytes\" wording -- the class Javadoc, the\nMAX_COLLECTION_ALLOCATION_PROPERTY Javadoc, the SystemLimitException message, and\nthe skipArray comment -- to say \"minimum encoded size is zero\" so the docs match\nthe condition under which the cap actually applies.\n\nAssisted-by: GitHub Copilot:claude-opus-4.8\n\n* AVRO-4300: [java] Half-open range in enum messages; finish zero-byte reword\n\nAddress review feedback:\n- The enum out-of-range messages said \"max is \u003csize\u003e\", implying \u003csize\u003e is a\n  valid index. Reword to the half-open \"must be in [0, \u003csize\u003e)\" to match the\n  actual check and the union messages, in ResolvingDecoder (both the\n  no-adjustments and adjustments branches), FastReaderBuilder, and\n  ValidatingDecoder.\n- Reword the remaining \"encodes to zero bytes\" wording in the\n  checkMaxCollectionAllocation Javadoc to \"minimum encoded size is zero\"\n  (including the recursive-schema case), matching isZeroByteSchema.\n\nAssisted-by: GitHub Copilot:claude-opus-4.8\n\n* AVRO-4300: [java] Enforce structural cap when skipping zero-byte arrays; tidy\n\nAddress review feedback:\n- skip(ARRAY) bounded zero-byte-element arrays only by the heap-aware allocation\n  cap, so the configurable structural collection limit\n  (MAX_COLLECTION_LENGTH_PROPERTY) was not enforced cumulatively and a large\n  count split into many blocks could drive a long skip loop. Always enforce\n  checkMaxCollectionLength cumulatively, and additionally\n  checkMaxCollectionAllocation for zero-byte schemas.\n- FastReaderBuilder.checkArrayBlock: skip the ensureAvailableCollectionBytes\n  call for zero-byte elements (it recomputes minBytesPerElement and no-ops),\n  applying the allocation cap directly instead.\n- Reword the checkMaxCollectionAllocation summary line from \"zero-byte-encoded\"\n  to \"minimum encoded size is zero\".\n\nAssisted-by: GitHub Copilot:claude-opus-4.8\n\n* AVRO-4300: [java] Reword defaultMaxCollectionAllocation Javadoc\n\nUpdate the last \"zero-byte-encoded\" wording (the private\ndefaultMaxCollectionAllocation helper) to \"minimum encoded size is zero\",\nconsistent with the public property/Javadoc and the isZeroByteSchema predicate.\n\nAssisted-by: GitHub Copilot:claude-opus-4.8\n\n* AVRO-4300: [java] Reword last zero-byte field doc; sort test imports\n\n- Reword the maxCollectionAllocation field Javadoc from \"zero-byte-encoded\" to\n  \"minimum encoded size is zero\".\n- Sort the java.io imports in TestGenericDatumReader (BufferedInputStream before\n  the ByteArray* imports) to satisfy Spotless.\n\nAssisted-by: GitHub Copilot:claude-opus-4.8\n\n* AVRO-4300: [java] Reject Long.MIN_VALUE and negative byte-size in doSkipItems\n\ndoSkipItems accepted a Long.MIN_VALUE block count (treating it as a byte-sized\nblock and continuing to skip), inconsistent with doReadItemCount which rejects\nit. Reject Long.MIN_VALUE, and also reject a negative block byte-size, so the\nskip path fails fast on malformed input like the read path.\n\nAssisted-by: GitHub Copilot:claude-opus-4.8\n\n* AVRO-4300: [java] Reject negative block byte-size in doReadItemCount\n\ndoReadItemCount consumed the block byte-size for a negative-count block without\nvalidating it. doSkipItems now rejects a negative byte-size, so the read path\ndoes the same for consistency and to reject malformed encodings.\n\nAssisted-by: GitHub Copilot:claude-opus-4.8\n\n* AVRO-4300: [java] Clarify test Javadoc: trailing 0L varint, not \"no data\"\n\nThe huge-collection matrix payload includes a trailing 0L varint (an element\nvalue for arrays, a 0-length key for maps); reword \"no element data\" to reflect\nthat.\n\nAssisted-by: GitHub Copilot:claude-opus-4.8\n\n* AVRO-4300: [java] Reword heap-fraction Javadoc to the actual predicate\n\nReword the DEFAULT_MAX_COLLECTION_ALLOCATION_HEAP_FRACTION Javadoc from\n\"zero-byte elements\" to \"elements whose minimum encoded size is zero\".\n\nAssisted-by: GitHub Copilot:claude-opus-4.8\n\n* AVRO-4300: [java] Make array preallocation-clamp test regression-proof\n\narrayHugeCountOnStreamClampsPreallocation only asserted an EOFException, which a\nreintroduced new Object[(int) count] preallocation could still satisfy on a\nlarge-heap JVM (allocating ~200M slots then hitting EOF). Override newArray to\nrecord the largest requested capacity and assert it stays clamped to\ninitialCollectionCapacity, and assert remainingBytes() \u003d\u003d -1 to confirm the\nunknown-remaining-bytes precondition.\n\nAssisted-by: GitHub Copilot:claude-opus-4.8\n\n* AVRO-4300: [java] Address review nits: use isZeroByteSchema, tidy block-count guards\n\nApply RyanSkraba\u0027s review feedback:\n- GenericDatumReader.readArray uses the isZeroByteSchema helper instead\n  of inlining minBytesPerElement \u003d\u003d 0, matching skip().\n- BinaryDecoder.doReadItemCount rejects Long.MIN_VALUE before consuming\n  the block byte-size, so no readLong runs once the count is invalid.\n- BinaryDecoder.doSkipItems drops the readLong before throwing on an\n  invalid Long.MIN_VALUE count, consistent with doReadItemCount.\n- FastReaderBuilder.createArrayReader drops the redundant comment;\n  the rationale is documented on checkArrayBlock."
    },
    {
      "commit": "f3bb10eaea1f03eb17893bc779eb26213da8177c",
      "tree": "080779c7d177f24f99e63c59d402342e829f6fad",
      "parents": [
        "cc134b3ff6016d86a5f97798afc77ef1a47b7d73"
      ],
      "author": {
        "name": "Harsh Srivastava",
        "email": "76532840+HarshDevelops@users.noreply.github.com",
        "time": "Sun Jul 19 18:39:59 2026 +0530"
      },
      "committer": {
        "name": "GitHub",
        "email": "noreply@github.com",
        "time": "Sun Jul 19 15:09:59 2026 +0200"
      },
      "message": "AVRO-4268: BytesWritableConverter should respect logical length (#3878)\n\nBytesWritable.getBytes() returns the backing array, which can be larger\nthan the logical length reported by BytesWritable.getLength(). Wrap\ninput.getBytes() with the actual length so the Avro bytes value reflects\nthe caller\u0027s data, not unused backing-array capacity.\n\nAdds convertBytesWritableRespectsLogicalLength to cover the regression.\n\nSigned-off-by: Harsh Srivastava \u003charsh10822@gmail.com\u003e"
    },
    {
      "commit": "cc134b3ff6016d86a5f97798afc77ef1a47b7d73",
      "tree": "e83478d090b0cd813ce8a3030532d9d2dbbfb8d2",
      "parents": [
        "43096d0457200af54800c8c55bd2074bb9d5b548"
      ],
      "author": {
        "name": "mohammed arib",
        "email": "arib@bugqore.com",
        "time": "Sun Jul 19 16:35:59 2026 +0530"
      },
      "committer": {
        "name": "GitHub",
        "email": "noreply@github.com",
        "time": "Sun Jul 19 13:05:59 2026 +0200"
      },
      "message": "MINOR: [c++] reject lone low surrogate U+DFFF in JSON decoder (#3841)\n\nThe lone-surrogate check used an exclusive upper bound (n \u003c 0xdfff), so the last low surrogate U+DFFF slipped through and was emitted as the invalid UTF-8 sequence ED BF BF; make the bound inclusive to match the trailing-surrogate validation in the same function."
    },
    {
      "commit": "43096d0457200af54800c8c55bd2074bb9d5b548",
      "tree": "98d1e4ae7850d0fc257dbc3c0aacdc59b392c7e2",
      "parents": [
        "2c8e71098a4d11e52a451ecb1220ff21b6da4c4c"
      ],
      "author": {
        "name": "dependabot[bot]",
        "email": "49699333+dependabot[bot]@users.noreply.github.com",
        "time": "Thu Jul 16 18:29:56 2026 +0200"
      },
      "committer": {
        "name": "GitHub",
        "email": "noreply@github.com",
        "time": "Thu Jul 16 18:29:56 2026 +0200"
      },
      "message": "Bump postcss from 8.5.16 to 8.5.17 in /doc (#3870)\n\nBumps [postcss](https://github.com/postcss/postcss) from 8.5.16 to 8.5.17.\n- [Release notes](https://github.com/postcss/postcss/releases)\n- [Changelog](https://github.com/postcss/postcss/blob/main/CHANGELOG.md)\n- [Commits](https://github.com/postcss/postcss/compare/8.5.16...8.5.17)\n\n---\nupdated-dependencies:\n- dependency-name: postcss\n  dependency-version: 8.5.17\n  dependency-type: direct:development\n  update-type: version-update:semver-patch\n...\n\nSigned-off-by: dependabot[bot] \u003csupport@github.com\u003e\nCo-authored-by: dependabot[bot] \u003c49699333+dependabot[bot]@users.noreply.github.com\u003e"
    },
    {
      "commit": "2c8e71098a4d11e52a451ecb1220ff21b6da4c4c",
      "tree": "b689476a9fc2fdb9b2183ae8feef423f78f4ea94",
      "parents": [
        "8b34f8be0068fc99477c989a51c124118d45a73f"
      ],
      "author": {
        "name": "dependabot[bot]",
        "email": "49699333+dependabot[bot]@users.noreply.github.com",
        "time": "Thu Jul 16 18:29:05 2026 +0200"
      },
      "committer": {
        "name": "GitHub",
        "email": "noreply@github.com",
        "time": "Thu Jul 16 18:29:05 2026 +0200"
      },
      "message": "Bump grpc.version from 1.82.1 to 1.82.2 in /lang/java (#3867)\n\nBumps `grpc.version` from 1.82.1 to 1.82.2.\n\nUpdates `io.grpc:grpc-core` from 1.82.1 to 1.82.2\n- [Release notes](https://github.com/grpc/grpc-java/releases)\n- [Commits](https://github.com/grpc/grpc-java/compare/v1.82.1...v1.82.2)\n\nUpdates `io.grpc:grpc-stub` from 1.82.1 to 1.82.2\n- [Release notes](https://github.com/grpc/grpc-java/releases)\n- [Commits](https://github.com/grpc/grpc-java/compare/v1.82.1...v1.82.2)\n\nUpdates `io.grpc:grpc-netty` from 1.82.1 to 1.82.2\n- [Release notes](https://github.com/grpc/grpc-java/releases)\n- [Commits](https://github.com/grpc/grpc-java/compare/v1.82.1...v1.82.2)\n\n---\nupdated-dependencies:\n- dependency-name: io.grpc:grpc-core\n  dependency-version: 1.82.2\n  dependency-type: direct:production\n  update-type: version-update:semver-patch\n- dependency-name: io.grpc:grpc-stub\n  dependency-version: 1.82.2\n  dependency-type: direct:production\n  update-type: version-update:semver-patch\n- dependency-name: io.grpc:grpc-netty\n  dependency-version: 1.82.2\n  dependency-type: direct:development\n  update-type: version-update:semver-patch\n...\n\nSigned-off-by: dependabot[bot] \u003csupport@github.com\u003e\nCo-authored-by: dependabot[bot] \u003c49699333+dependabot[bot]@users.noreply.github.com\u003e"
    },
    {
      "commit": "8b34f8be0068fc99477c989a51c124118d45a73f",
      "tree": "aa691249e7d573c823d3b8128bdb5d4fe5aef2d4",
      "parents": [
        "8bdb8c612c35bea9632ea48ab2b8d285c9007ed1"
      ],
      "author": {
        "name": "dependabot[bot]",
        "email": "49699333+dependabot[bot]@users.noreply.github.com",
        "time": "Thu Jul 16 18:29:00 2026 +0200"
      },
      "committer": {
        "name": "GitHub",
        "email": "noreply@github.com",
        "time": "Thu Jul 16 18:29:00 2026 +0200"
      },
      "message": "Update mypy requirement from \u003c2.2.0 to \u003c2.3.0 in /lang/py (#3868)\n\nUpdates the requirements on [mypy](https://github.com/python/mypy) to permit the latest version.\n- [Changelog](https://github.com/python/mypy/blob/master/CHANGELOG.md)\n- [Commits](https://github.com/python/mypy/compare/v0.1.0...v2.2.0)\n\n---\nupdated-dependencies:\n- dependency-name: mypy\n  dependency-version: 2.2.0\n  dependency-type: direct:development\n...\n\nSigned-off-by: dependabot[bot] \u003csupport@github.com\u003e\nCo-authored-by: dependabot[bot] \u003c49699333+dependabot[bot]@users.noreply.github.com\u003e"
    },
    {
      "commit": "8bdb8c612c35bea9632ea48ab2b8d285c9007ed1",
      "tree": "b6b1aa7c95e219583bc327305c7a35e7587a911a",
      "parents": [
        "19d83d27ed8f5cf040ab6ad067db1503910c8caf"
      ],
      "author": {
        "name": "dependabot[bot]",
        "email": "49699333+dependabot[bot]@users.noreply.github.com",
        "time": "Thu Jul 16 18:28:44 2026 +0200"
      },
      "committer": {
        "name": "GitHub",
        "email": "noreply@github.com",
        "time": "Thu Jul 16 18:28:44 2026 +0200"
      },
      "message": "Bump astral-sh/setup-uv from 8.2.0 to 8.3.2 (#3871)\n\nBumps [astral-sh/setup-uv](https://github.com/astral-sh/setup-uv) from 8.2.0 to 8.3.2.\n- [Release notes](https://github.com/astral-sh/setup-uv/releases)\n- [Commits](https://github.com/astral-sh/setup-uv/compare/fac544c07dec837d0ccb6301d7b5580bf5edae39...11f9893b081a58869d3b5fccaea48c9e9e46f990)\n\n---\nupdated-dependencies:\n- dependency-name: astral-sh/setup-uv\n  dependency-version: 8.3.2\n  dependency-type: direct:production\n  update-type: version-update:semver-minor\n...\n\nSigned-off-by: dependabot[bot] \u003csupport@github.com\u003e\nCo-authored-by: dependabot[bot] \u003c49699333+dependabot[bot]@users.noreply.github.com\u003e"
    },
    {
      "commit": "19d83d27ed8f5cf040ab6ad067db1503910c8caf",
      "tree": "03b96cfd7e68da197070b7ccfe4a06b1f44b114c",
      "parents": [
        "0c0ca3fc1e3439fd5dc12cbf38a93a89d685daf5"
      ],
      "author": {
        "name": "dependabot[bot]",
        "email": "49699333+dependabot[bot]@users.noreply.github.com",
        "time": "Thu Jul 16 18:28:26 2026 +0200"
      },
      "committer": {
        "name": "GitHub",
        "email": "noreply@github.com",
        "time": "Thu Jul 16 18:28:26 2026 +0200"
      },
      "message": "Bump com.fasterxml.jackson:jackson-bom in /lang/java (#3873)\n\nBumps [com.fasterxml.jackson:jackson-bom](https://github.com/FasterXML/jackson-bom) from 2.22.0 to 2.22.1.\n- [Commits](https://github.com/FasterXML/jackson-bom/compare/jackson-bom-2.22.0...jackson-bom-2.22.1)\n\n---\nupdated-dependencies:\n- dependency-name: com.fasterxml.jackson:jackson-bom\n  dependency-version: 2.22.1\n  dependency-type: direct:production\n  update-type: version-update:semver-patch\n...\n\nSigned-off-by: dependabot[bot] \u003csupport@github.com\u003e\nCo-authored-by: dependabot[bot] \u003c49699333+dependabot[bot]@users.noreply.github.com\u003e"
    },
    {
      "commit": "0c0ca3fc1e3439fd5dc12cbf38a93a89d685daf5",
      "tree": "18153495c0ac20a139e76ae36d7b10670fb2977d",
      "parents": [
        "bb72c294b1c9a6290b6b190edef75fb51340bc2e"
      ],
      "author": {
        "name": "dependabot[bot]",
        "email": "49699333+dependabot[bot]@users.noreply.github.com",
        "time": "Thu Jul 16 18:28:15 2026 +0200"
      },
      "committer": {
        "name": "GitHub",
        "email": "noreply@github.com",
        "time": "Thu Jul 16 18:28:15 2026 +0200"
      },
      "message": "Bump io.netty:netty-bom from 4.2.15.Final to 4.2.16.Final in /lang/java (#3874)\n\nBumps [io.netty:netty-bom](https://github.com/netty/netty) from 4.2.15.Final to 4.2.16.Final.\n- [Release notes](https://github.com/netty/netty/releases)\n- [Commits](https://github.com/netty/netty/compare/netty-4.2.15.Final...netty-4.2.16.Final)\n\n---\nupdated-dependencies:\n- dependency-name: io.netty:netty-bom\n  dependency-version: 4.2.16.Final\n  dependency-type: direct:production\n  update-type: version-update:semver-patch\n...\n\nSigned-off-by: dependabot[bot] \u003csupport@github.com\u003e\nCo-authored-by: dependabot[bot] \u003c49699333+dependabot[bot]@users.noreply.github.com\u003e"
    },
    {
      "commit": "bb72c294b1c9a6290b6b190edef75fb51340bc2e",
      "tree": "b0403f619087040186c81b760150c151cf593acb",
      "parents": [
        "e1386c1b12d3b8abbe4a8f46e42ef3d88f2ced0c"
      ],
      "author": {
        "name": "Ismaël Mejía",
        "email": "iemejia@gmail.com",
        "time": "Mon Apr 06 19:54:14 2026 +0000"
      },
      "committer": {
        "name": "Ismaël Mejía",
        "email": "iemejia@gmail.com",
        "time": "Sat Jul 11 11:37:22 2026 +0200"
      },
      "message": "AVRO-4242: [Java] Fix NPE in DataFileStream and DataFileReader when schema metadata is missing\n\nMalformed Avro container files without the \u0027avro.schema\u0027 metadata entry\ncaused a NullPointerException in both DataFileStream and DataFileReader12\nwhen the null value was passed directly to Schema.Parser.parse(). Replace\ninline parsing with null-safe helper methods that throw a descriptive\nIOException instead.\n"
    },
    {
      "commit": "e1386c1b12d3b8abbe4a8f46e42ef3d88f2ced0c",
      "tree": "7fcc3a08687c4e24c2d4c5c4219d62a5d3454012",
      "parents": [
        "7f08eb1e9cb751273013f6f8c575580420996243"
      ],
      "author": {
        "name": "dependabot[bot]",
        "email": "49699333+dependabot[bot]@users.noreply.github.com",
        "time": "Fri Jul 03 19:48:30 2026 +0200"
      },
      "committer": {
        "name": "GitHub",
        "email": "noreply@github.com",
        "time": "Fri Jul 03 19:48:30 2026 +0200"
      },
      "message": "Bump autoprefixer from 10.5.0 to 10.5.2 in /doc (#3834)\n\nBumps [autoprefixer](https://github.com/postcss/autoprefixer) from 10.5.0 to 10.5.2.\n- [Release notes](https://github.com/postcss/autoprefixer/releases)\n- [Changelog](https://github.com/postcss/autoprefixer/blob/main/CHANGELOG.md)\n- [Commits](https://github.com/postcss/autoprefixer/compare/10.5.0...10.5.2)\n\n---\nupdated-dependencies:\n- dependency-name: autoprefixer\n  dependency-version: 10.5.2\n  dependency-type: direct:development\n  update-type: version-update:semver-patch\n...\n\nSigned-off-by: dependabot[bot] \u003csupport@github.com\u003e\nCo-authored-by: dependabot[bot] \u003c49699333+dependabot[bot]@users.noreply.github.com\u003e"
    },
    {
      "commit": "7f08eb1e9cb751273013f6f8c575580420996243",
      "tree": "616c636b1eb0a1c66775f480525acd0725821c1b",
      "parents": [
        "5b63fb4161d8753c78e0cfd3a21010c000900bdf"
      ],
      "author": {
        "name": "dependabot[bot]",
        "email": "49699333+dependabot[bot]@users.noreply.github.com",
        "time": "Fri Jul 03 19:43:23 2026 +0200"
      },
      "committer": {
        "name": "GitHub",
        "email": "noreply@github.com",
        "time": "Fri Jul 03 19:43:23 2026 +0200"
      },
      "message": "Bump postcss from 8.5.15 to 8.5.16 in /doc (#3832)\n\nBumps [postcss](https://github.com/postcss/postcss) from 8.5.15 to 8.5.16.\n- [Release notes](https://github.com/postcss/postcss/releases)\n- [Changelog](https://github.com/postcss/postcss/blob/main/CHANGELOG.md)\n- [Commits](https://github.com/postcss/postcss/compare/8.5.15...8.5.16)\n\n---\nupdated-dependencies:\n- dependency-name: postcss\n  dependency-version: 8.5.16\n  dependency-type: direct:development\n  update-type: version-update:semver-patch\n...\n\nSigned-off-by: dependabot[bot] \u003csupport@github.com\u003e\nCo-authored-by: dependabot[bot] \u003c49699333+dependabot[bot]@users.noreply.github.com\u003e"
    },
    {
      "commit": "5b63fb4161d8753c78e0cfd3a21010c000900bdf",
      "tree": "6f6063744a46c7b733019def6106f1aa2197eeee",
      "parents": [
        "777115078052380154fc99be32a9ae188919a522"
      ],
      "author": {
        "name": "dependabot[bot]",
        "email": "49699333+dependabot[bot]@users.noreply.github.com",
        "time": "Fri Jul 03 19:43:16 2026 +0200"
      },
      "committer": {
        "name": "GitHub",
        "email": "noreply@github.com",
        "time": "Fri Jul 03 19:43:16 2026 +0200"
      },
      "message": "Bump actions/cache from 5 to 6 (#3833)\n\nBumps [actions/cache](https://github.com/actions/cache) from 5 to 6.\n- [Release notes](https://github.com/actions/cache/releases)\n- [Changelog](https://github.com/actions/cache/blob/main/RELEASES.md)\n- [Commits](https://github.com/actions/cache/compare/v5...v6)\n\n---\nupdated-dependencies:\n- dependency-name: actions/cache\n  dependency-version: \u00276\u0027\n  dependency-type: direct:production\n  update-type: version-update:semver-major\n...\n\nSigned-off-by: dependabot[bot] \u003csupport@github.com\u003e\nCo-authored-by: dependabot[bot] \u003c49699333+dependabot[bot]@users.noreply.github.com\u003e"
    },
    {
      "commit": "777115078052380154fc99be32a9ae188919a522",
      "tree": "f06b5b51dfc3f249f46f1fe71fe7b60315111ffc",
      "parents": [
        "87501fee7da2fa65224f40b163b167569ee3acd3"
      ],
      "author": {
        "name": "dependabot[bot]",
        "email": "49699333+dependabot[bot]@users.noreply.github.com",
        "time": "Fri Jul 03 19:43:08 2026 +0200"
      },
      "committer": {
        "name": "GitHub",
        "email": "noreply@github.com",
        "time": "Fri Jul 03 19:43:08 2026 +0200"
      },
      "message": "Bump grpc.version from 1.82.0 to 1.82.1 in /lang/java (#3831)\n\nBumps `grpc.version` from 1.82.0 to 1.82.1.\n\nUpdates `io.grpc:grpc-core` from 1.82.0 to 1.82.1\n- [Release notes](https://github.com/grpc/grpc-java/releases)\n- [Commits](https://github.com/grpc/grpc-java/compare/v1.82.0...v1.82.1)\n\nUpdates `io.grpc:grpc-stub` from 1.82.0 to 1.82.1\n- [Release notes](https://github.com/grpc/grpc-java/releases)\n- [Commits](https://github.com/grpc/grpc-java/compare/v1.82.0...v1.82.1)\n\nUpdates `io.grpc:grpc-netty` from 1.82.0 to 1.82.1\n- [Release notes](https://github.com/grpc/grpc-java/releases)\n- [Commits](https://github.com/grpc/grpc-java/compare/v1.82.0...v1.82.1)\n\n---\nupdated-dependencies:\n- dependency-name: io.grpc:grpc-core\n  dependency-version: 1.82.1\n  dependency-type: direct:production\n  update-type: version-update:semver-patch\n- dependency-name: io.grpc:grpc-stub\n  dependency-version: 1.82.1\n  dependency-type: direct:production\n  update-type: version-update:semver-patch\n- dependency-name: io.grpc:grpc-netty\n  dependency-version: 1.82.1\n  dependency-type: direct:development\n  update-type: version-update:semver-patch\n...\n\nSigned-off-by: dependabot[bot] \u003csupport@github.com\u003e\nCo-authored-by: dependabot[bot] \u003c49699333+dependabot[bot]@users.noreply.github.com\u003e"
    },
    {
      "commit": "87501fee7da2fa65224f40b163b167569ee3acd3",
      "tree": "7113107c46509f2bfc7c6de6577940f610b502ba",
      "parents": [
        "bbbdd53fa256827819d49026b9795bf069d2b3cd"
      ],
      "author": {
        "name": "dependabot[bot]",
        "email": "49699333+dependabot[bot]@users.noreply.github.com",
        "time": "Fri Jul 03 19:43:01 2026 +0200"
      },
      "committer": {
        "name": "GitHub",
        "email": "noreply@github.com",
        "time": "Fri Jul 03 19:43:01 2026 +0200"
      },
      "message": "Bump com.diffplug.spotless:spotless-maven-plugin in /lang/java (#3829)\n\nBumps [com.diffplug.spotless:spotless-maven-plugin](https://github.com/diffplug/spotless) from 3.6.0 to 3.7.0.\n- [Release notes](https://github.com/diffplug/spotless/releases)\n- [Changelog](https://github.com/diffplug/spotless/blob/main/CHANGES.md)\n- [Commits](https://github.com/diffplug/spotless/compare/maven/3.6.0...maven/3.7.0)\n\n---\nupdated-dependencies:\n- dependency-name: com.diffplug.spotless:spotless-maven-plugin\n  dependency-version: 3.7.0\n  dependency-type: direct:production\n  update-type: version-update:semver-minor\n...\n\nSigned-off-by: dependabot[bot] \u003csupport@github.com\u003e\nCo-authored-by: dependabot[bot] \u003c49699333+dependabot[bot]@users.noreply.github.com\u003e"
    },
    {
      "commit": "bbbdd53fa256827819d49026b9795bf069d2b3cd",
      "tree": "787d5e6471890e1c5a141678561baceb4acb1162",
      "parents": [
        "bc1361576cc3e2822e11cdc189f922d614c67cff"
      ],
      "author": {
        "name": "dependabot[bot]",
        "email": "49699333+dependabot[bot]@users.noreply.github.com",
        "time": "Fri Jul 03 19:42:53 2026 +0200"
      },
      "committer": {
        "name": "GitHub",
        "email": "noreply@github.com",
        "time": "Fri Jul 03 19:42:53 2026 +0200"
      },
      "message": "Bump org.cyclonedx:cyclonedx-maven-plugin in /lang/java (#3828)\n\nBumps [org.cyclonedx:cyclonedx-maven-plugin](https://github.com/CycloneDX/cyclonedx-maven-plugin) from 2.9.1 to 2.9.2.\n- [Release notes](https://github.com/CycloneDX/cyclonedx-maven-plugin/releases)\n- [Commits](https://github.com/CycloneDX/cyclonedx-maven-plugin/compare/cyclonedx-maven-plugin-2.9.1...cyclonedx-maven-plugin-2.9.2)\n\n---\nupdated-dependencies:\n- dependency-name: org.cyclonedx:cyclonedx-maven-plugin\n  dependency-version: 2.9.2\n  dependency-type: direct:production\n  update-type: version-update:semver-patch\n...\n\nSigned-off-by: dependabot[bot] \u003csupport@github.com\u003e\nCo-authored-by: dependabot[bot] \u003c49699333+dependabot[bot]@users.noreply.github.com\u003e"
    },
    {
      "commit": "bc1361576cc3e2822e11cdc189f922d614c67cff",
      "tree": "b9ebe2df0ccf578b07af4bd69f5700213e1b9e7e",
      "parents": [
        "840dc8139f4b3d1bfa8e8c8f1ac3be949b440634"
      ],
      "author": {
        "name": "dependabot[bot]",
        "email": "49699333+dependabot[bot]@users.noreply.github.com",
        "time": "Fri Jul 03 19:42:45 2026 +0200"
      },
      "committer": {
        "name": "GitHub",
        "email": "noreply@github.com",
        "time": "Fri Jul 03 19:42:45 2026 +0200"
      },
      "message": "Bump actions/checkout from 6 to 7 (#3827)\n\nBumps [actions/checkout](https://github.com/actions/checkout) from 6 to 7.\n- [Release notes](https://github.com/actions/checkout/releases)\n- [Changelog](https://github.com/actions/checkout/blob/main/CHANGELOG.md)\n- [Commits](https://github.com/actions/checkout/compare/v6...v7)\n\n---\nupdated-dependencies:\n- dependency-name: actions/checkout\n  dependency-version: \u00277\u0027\n  dependency-type: direct:production\n  update-type: version-update:semver-major\n...\n\nSigned-off-by: dependabot[bot] \u003csupport@github.com\u003e\nCo-authored-by: dependabot[bot] \u003c49699333+dependabot[bot]@users.noreply.github.com\u003e"
    },
    {
      "commit": "840dc8139f4b3d1bfa8e8c8f1ac3be949b440634",
      "tree": "0b9c9cf05c2a855768399b009e705d10c6b5a165",
      "parents": [
        "d85a45b4f53c3b74e6dab3ba9be48932e301b50b"
      ],
      "author": {
        "name": "Mattia Basone",
        "email": "mattia.basone@gmail.com",
        "time": "Fri Jun 19 11:48:20 2026 +0200"
      },
      "committer": {
        "name": "GitHub",
        "email": "noreply@github.com",
        "time": "Fri Jun 19 11:48:20 2026 +0200"
      },
      "message": "PHP - fix json_decode syntax error and set dev tools version (#3824)"
    },
    {
      "commit": "d85a45b4f53c3b74e6dab3ba9be48932e301b50b",
      "tree": "875d4956b15316e1c6f3e904a52816f1bb92e2f3",
      "parents": [
        "912ab25169ab829d5c523fd231b5abb286c4dbe1"
      ],
      "author": {
        "name": "KyleKim107",
        "email": "56135395+KyleKim107@users.noreply.github.com",
        "time": "Fri Jun 19 02:58:41 2026 -0500"
      },
      "committer": {
        "name": "GitHub",
        "email": "noreply@github.com",
        "time": "Fri Jun 19 10:58:41 2026 +0300"
      },
      "message": "Fix wrong schema accessor in avro_generic_map_class (#3823)"
    },
    {
      "commit": "912ab25169ab829d5c523fd231b5abb286c4dbe1",
      "tree": "1722d4ddf915102a4a251745f2664e9787acb715",
      "parents": [
        "4bec628b057d2c55447e8e228ceb20158b1c91a4"
      ],
      "author": {
        "name": "Emanuele Russo",
        "email": "150815706+emarussoo@users.noreply.github.com",
        "time": "Thu Jun 18 23:56:11 2026 +0200"
      },
      "committer": {
        "name": "GitHub",
        "email": "noreply@github.com",
        "time": "Thu Jun 18 23:56:11 2026 +0200"
      },
      "message": "AVRO-4269: Fix timestamp-nanos conversion before epoch (#3813)"
    },
    {
      "commit": "4bec628b057d2c55447e8e228ceb20158b1c91a4",
      "tree": "7804c632b5fe0ee05ecb30ab567c55aa848d26c5",
      "parents": [
        "3c972b03c88720e6bdad48fd0c488e5c79b00089"
      ],
      "author": {
        "name": "dependabot[bot]",
        "email": "49699333+dependabot[bot]@users.noreply.github.com",
        "time": "Mon Jun 15 20:23:15 2026 +0200"
      },
      "committer": {
        "name": "GitHub",
        "email": "noreply@github.com",
        "time": "Mon Jun 15 20:23:15 2026 +0200"
      },
      "message": "Bump System.CodeDom from 10.0.8 to 10.0.9 (#3821)\n\n---\nupdated-dependencies:\n- dependency-name: System.CodeDom\n  dependency-version: 10.0.9\n  dependency-type: direct:production\n  update-type: version-update:semver-patch\n...\n\nSigned-off-by: dependabot[bot] \u003csupport@github.com\u003e\nCo-authored-by: dependabot[bot] \u003c49699333+dependabot[bot]@users.noreply.github.com\u003e"
    },
    {
      "commit": "3c972b03c88720e6bdad48fd0c488e5c79b00089",
      "tree": "a82131bc1b2678bfe80f2053fdc0dcf68624ea6c",
      "parents": [
        "23436092e748acff9b4b2723cfaf9b12a2182869"
      ],
      "author": {
        "name": "dependabot[bot]",
        "email": "49699333+dependabot[bot]@users.noreply.github.com",
        "time": "Mon Jun 15 20:23:02 2026 +0200"
      },
      "committer": {
        "name": "GitHub",
        "email": "noreply@github.com",
        "time": "Mon Jun 15 20:23:02 2026 +0200"
      },
      "message": "Bump Microsoft.Build.Framework and Microsoft.Build.Utilities.Core (#3820)\n\nBumps Microsoft.Build.Framework from 18.6.3 to 18.7.1\nBumps Microsoft.Build.Utilities.Core from 18.6.3 to 18.7.1\n\n---\nupdated-dependencies:\n- dependency-name: Microsoft.Build.Framework\n  dependency-version: 18.7.1\n  dependency-type: direct:production\n  update-type: version-update:semver-minor\n- dependency-name: Microsoft.Build.Utilities.Core\n  dependency-version: 18.7.1\n  dependency-type: direct:production\n  update-type: version-update:semver-minor\n...\n\nSigned-off-by: dependabot[bot] \u003csupport@github.com\u003e\nCo-authored-by: dependabot[bot] \u003c49699333+dependabot[bot]@users.noreply.github.com\u003e"
    },
    {
      "commit": "23436092e748acff9b4b2723cfaf9b12a2182869",
      "tree": "2189105172fe0c7aa81263d8c5774c00ed941292",
      "parents": [
        "2ca939eb8ca01b4d29aae69dd405972424dd0ada"
      ],
      "author": {
        "name": "dependabot[bot]",
        "email": "49699333+dependabot[bot]@users.noreply.github.com",
        "time": "Mon Jun 15 20:22:51 2026 +0200"
      },
      "committer": {
        "name": "GitHub",
        "email": "noreply@github.com",
        "time": "Mon Jun 15 20:22:51 2026 +0200"
      },
      "message": "Bump com.google.protobuf:protobuf-java in /lang/java (#3818)\n\nBumps [com.google.protobuf:protobuf-java](https://github.com/protocolbuffers/protobuf) from 4.35.0 to 4.35.1.\n- [Release notes](https://github.com/protocolbuffers/protobuf/releases)\n- [Commits](https://github.com/protocolbuffers/protobuf/commits)\n\n---\nupdated-dependencies:\n- dependency-name: com.google.protobuf:protobuf-java\n  dependency-version: 4.35.1\n  dependency-type: direct:production\n  update-type: version-update:semver-patch\n...\n\nSigned-off-by: dependabot[bot] \u003csupport@github.com\u003e\nCo-authored-by: dependabot[bot] \u003c49699333+dependabot[bot]@users.noreply.github.com\u003e"
    },
    {
      "commit": "2ca939eb8ca01b4d29aae69dd405972424dd0ada",
      "tree": "a6f7bf5b52b1382ce5e36845368379682df94afd",
      "parents": [
        "d728cbcbe0eabf76de41e4365e96a2532887bbd2"
      ],
      "author": {
        "name": "dependabot[bot]",
        "email": "49699333+dependabot[bot]@users.noreply.github.com",
        "time": "Mon Jun 15 20:22:41 2026 +0200"
      },
      "committer": {
        "name": "GitHub",
        "email": "noreply@github.com",
        "time": "Mon Jun 15 20:22:41 2026 +0200"
      },
      "message": "Bump grpc.version from 1.81.0 to 1.82.0 in /lang/java (#3817)\n\nBumps `grpc.version` from 1.81.0 to 1.82.0.\n\nUpdates `io.grpc:grpc-core` from 1.81.0 to 1.82.0\n- [Release notes](https://github.com/grpc/grpc-java/releases)\n- [Commits](https://github.com/grpc/grpc-java/compare/v1.81.0...v1.82.0)\n\nUpdates `io.grpc:grpc-stub` from 1.81.0 to 1.82.0\n- [Release notes](https://github.com/grpc/grpc-java/releases)\n- [Commits](https://github.com/grpc/grpc-java/compare/v1.81.0...v1.82.0)\n\nUpdates `io.grpc:grpc-netty` from 1.81.0 to 1.82.0\n- [Release notes](https://github.com/grpc/grpc-java/releases)\n- [Commits](https://github.com/grpc/grpc-java/compare/v1.81.0...v1.82.0)\n\n---\nupdated-dependencies:\n- dependency-name: io.grpc:grpc-core\n  dependency-version: 1.82.0\n  dependency-type: direct:production\n  update-type: version-update:semver-minor\n- dependency-name: io.grpc:grpc-stub\n  dependency-version: 1.82.0\n  dependency-type: direct:production\n  update-type: version-update:semver-minor\n- dependency-name: io.grpc:grpc-netty\n  dependency-version: 1.82.0\n  dependency-type: direct:development\n  update-type: version-update:semver-minor\n...\n\nSigned-off-by: dependabot[bot] \u003csupport@github.com\u003e\nCo-authored-by: dependabot[bot] \u003c49699333+dependabot[bot]@users.noreply.github.com\u003e"
    },
    {
      "commit": "d728cbcbe0eabf76de41e4365e96a2532887bbd2",
      "tree": "8a9bc03b9e1fe582fd82d0778e27ef050abaad54",
      "parents": [
        "0f18ca801f25fa9435d727abba9fb979f9bde662"
      ],
      "author": {
        "name": "dependabot[bot]",
        "email": "49699333+dependabot[bot]@users.noreply.github.com",
        "time": "Mon Jun 15 20:22:11 2026 +0200"
      },
      "committer": {
        "name": "GitHub",
        "email": "noreply@github.com",
        "time": "Mon Jun 15 20:22:11 2026 +0200"
      },
      "message": "Bump com.github.luben:zstd-jni from 1.5.7-10 to 1.5.7-11 in /lang/java (#3816)\n\nBumps [com.github.luben:zstd-jni](https://github.com/luben/zstd-jni) from 1.5.7-10 to 1.5.7-11.\n- [Commits](https://github.com/luben/zstd-jni/commits/v1.5.7-11)\n\n---\nupdated-dependencies:\n- dependency-name: com.github.luben:zstd-jni\n  dependency-version: 1.5.7-11\n  dependency-type: direct:production\n  update-type: version-update:semver-patch\n...\n\nSigned-off-by: dependabot[bot] \u003csupport@github.com\u003e\nCo-authored-by: dependabot[bot] \u003c49699333+dependabot[bot]@users.noreply.github.com\u003e"
    },
    {
      "commit": "0f18ca801f25fa9435d727abba9fb979f9bde662",
      "tree": "10240a542af7fa40c5dda000ff9eb7c3832ed9d3",
      "parents": [
        "76fadbfcb73f9173fed535700518d6a41e4c719a"
      ],
      "author": {
        "name": "dependabot[bot]",
        "email": "49699333+dependabot[bot]@users.noreply.github.com",
        "time": "Thu Jun 11 15:19:35 2026 +0200"
      },
      "committer": {
        "name": "GitHub",
        "email": "noreply@github.com",
        "time": "Thu Jun 11 15:19:35 2026 +0200"
      },
      "message": "Bump com.github.luben:zstd-jni from 1.5.7-9 to 1.5.7-10 in /lang/java (#3812)\n\nBumps [com.github.luben:zstd-jni](https://github.com/luben/zstd-jni) from 1.5.7-9 to 1.5.7-10.\n- [Commits](https://github.com/luben/zstd-jni/commits)\n\n---\nupdated-dependencies:\n- dependency-name: com.github.luben:zstd-jni\n  dependency-version: 1.5.7-10\n  dependency-type: direct:production\n  update-type: version-update:semver-patch\n...\n\nSigned-off-by: dependabot[bot] \u003csupport@github.com\u003e\nCo-authored-by: dependabot[bot] \u003c49699333+dependabot[bot]@users.noreply.github.com\u003e"
    },
    {
      "commit": "76fadbfcb73f9173fed535700518d6a41e4c719a",
      "tree": "44db91133ddfa55b42ea6797ee4752e0b204cdf2",
      "parents": [
        "99bfb9eb0ed73efa8293435e7de5bd568c784261"
      ],
      "author": {
        "name": "dependabot[bot]",
        "email": "49699333+dependabot[bot]@users.noreply.github.com",
        "time": "Thu Jun 11 15:19:27 2026 +0200"
      },
      "committer": {
        "name": "GitHub",
        "email": "noreply@github.com",
        "time": "Thu Jun 11 15:19:27 2026 +0200"
      },
      "message": "Bump astral-sh/setup-uv from 8.1.0 to 8.2.0 (#3811)\n\nBumps [astral-sh/setup-uv](https://github.com/astral-sh/setup-uv) from 8.1.0 to 8.2.0.\n- [Release notes](https://github.com/astral-sh/setup-uv/releases)\n- [Commits](https://github.com/astral-sh/setup-uv/compare/08807647e7069bb48b6ef5acd8ec9567f424441b...fac544c07dec837d0ccb6301d7b5580bf5edae39)\n\n---\nupdated-dependencies:\n- dependency-name: astral-sh/setup-uv\n  dependency-version: 8.2.0\n  dependency-type: direct:production\n  update-type: version-update:semver-minor\n...\n\nSigned-off-by: dependabot[bot] \u003csupport@github.com\u003e\nCo-authored-by: dependabot[bot] \u003c49699333+dependabot[bot]@users.noreply.github.com\u003e"
    },
    {
      "commit": "99bfb9eb0ed73efa8293435e7de5bd568c784261",
      "tree": "5fd80acbd224ff1175b49c2b18e678921bef5cf3",
      "parents": [
        "ec31e8b81517138779fa4797e8432cf39bba9801"
      ],
      "author": {
        "name": "dependabot[bot]",
        "email": "49699333+dependabot[bot]@users.noreply.github.com",
        "time": "Thu Jun 11 15:19:12 2026 +0200"
      },
      "committer": {
        "name": "GitHub",
        "email": "noreply@github.com",
        "time": "Thu Jun 11 15:19:12 2026 +0200"
      },
      "message": "Bump io.netty:netty-bom from 4.2.14.Final to 4.2.15.Final in /lang/java (#3810)\n\nBumps [io.netty:netty-bom](https://github.com/netty/netty) from 4.2.14.Final to 4.2.15.Final.\n- [Release notes](https://github.com/netty/netty/releases)\n- [Commits](https://github.com/netty/netty/compare/netty-4.2.14.Final...netty-4.2.15.Final)\n\n---\nupdated-dependencies:\n- dependency-name: io.netty:netty-bom\n  dependency-version: 4.2.15.Final\n  dependency-type: direct:production\n  update-type: version-update:semver-patch\n...\n\nSigned-off-by: dependabot[bot] \u003csupport@github.com\u003e\nCo-authored-by: dependabot[bot] \u003c49699333+dependabot[bot]@users.noreply.github.com\u003e"
    },
    {
      "commit": "ec31e8b81517138779fa4797e8432cf39bba9801",
      "tree": "ca1e81dcade97fcf1c9869a062ee19041138a77c",
      "parents": [
        "6444e8d5e86baa85ab5962a8bc275838e8c364b6"
      ],
      "author": {
        "name": "dependabot[bot]",
        "email": "49699333+dependabot[bot]@users.noreply.github.com",
        "time": "Thu Jun 11 15:19:00 2026 +0200"
      },
      "committer": {
        "name": "GitHub",
        "email": "noreply@github.com",
        "time": "Thu Jun 11 15:19:00 2026 +0200"
      },
      "message": "Bump com.fasterxml.jackson:jackson-bom in /lang/java (#3809)\n\nBumps [com.fasterxml.jackson:jackson-bom](https://github.com/FasterXML/jackson-bom) from 2.21.4 to 2.22.0.\n- [Commits](https://github.com/FasterXML/jackson-bom/compare/jackson-bom-2.21.4...jackson-bom-2.22.0)\n\n---\nupdated-dependencies:\n- dependency-name: com.fasterxml.jackson:jackson-bom\n  dependency-version: 2.22.0\n  dependency-type: direct:production\n  update-type: version-update:semver-minor\n...\n\nSigned-off-by: dependabot[bot] \u003csupport@github.com\u003e\nCo-authored-by: dependabot[bot] \u003c49699333+dependabot[bot]@users.noreply.github.com\u003e"
    },
    {
      "commit": "6444e8d5e86baa85ab5962a8bc275838e8c364b6",
      "tree": "822ef2d08462756958ed0cd9f77be518a7e43697",
      "parents": [
        "997d50d312613e921598aaed30b082f9bcf9c6ea"
      ],
      "author": {
        "name": "Gang Wu",
        "email": "ustcwg@gmail.com",
        "time": "Wed Jun 10 16:02:22 2026 +0800"
      },
      "committer": {
        "name": "GitHub",
        "email": "noreply@github.com",
        "time": "Wed Jun 10 11:02:22 2026 +0300"
      },
      "message": "MINOR: [C++] fix missing format_context when compiled with C++23 (#3815)"
    },
    {
      "commit": "997d50d312613e921598aaed30b082f9bcf9c6ea",
      "tree": "dc6916e830f17b5a978fc87029b937b719970d10",
      "parents": [
        "d77446e5d05cd68c28d09c1af800a428dea34e03"
      ],
      "author": {
        "name": "Gang Wu",
        "email": "ustcwg@gmail.com",
        "time": "Mon Jun 08 13:55:52 2026 +0800"
      },
      "committer": {
        "name": "GitHub",
        "email": "noreply@github.com",
        "time": "Mon Jun 08 08:55:52 2026 +0300"
      },
      "message": "MINOR: [C++] Add missing header \u003ctype_traits\u003e (#3808)"
    },
    {
      "commit": "d77446e5d05cd68c28d09c1af800a428dea34e03",
      "tree": "f579ae86b35e31516d19f66cbc5be08053bb90a0",
      "parents": [
        "2041bcdf12c4ce58d33d1853cfe3a016f2d790fe"
      ],
      "author": {
        "name": "Gang Wu",
        "email": "ustcwg@gmail.com",
        "time": "Wed Jun 03 04:07:22 2026 +0800"
      },
      "committer": {
        "name": "GitHub",
        "email": "noreply@github.com",
        "time": "Tue Jun 02 22:07:22 2026 +0200"
      },
      "message": "AVRO-XXX: [C++] Replace fmt with std::format and require C++20 (#3788)"
    },
    {
      "commit": "2041bcdf12c4ce58d33d1853cfe3a016f2d790fe",
      "tree": "aee628c5829d3b1bffb4d9ac6e982c4307dcc84a",
      "parents": [
        "bd70a0859b9d739aad0547aa61bd17291049773b"
      ],
      "author": {
        "name": "Fábio Lucas Carneiro",
        "email": "fabiolucas.carneiro@gmail.com",
        "time": "Tue Jun 02 20:04:24 2026 +0200"
      },
      "committer": {
        "name": "GitHub",
        "email": "noreply@github.com",
        "time": "Tue Jun 02 20:04:24 2026 +0200"
      },
      "message": "AVRO-4246: [c] Fix memory leak on failed decoding (#3732)\n\n* AVRO-4246: Add \u0027AVRO_READ_OR_FREE\u0027 macro.\n\n* AVRO-4246: Replace \u0027AVRO_READ\u0027 by \u0027AVRO_READ_OR_FREE\u0027 in \u0027read_string\u0027 and \u0027read_bytes\u0027 functions.\n\n* AVRO-4246: Add \u0027test_avro_4246.c\u0027 to test suite.\n\n---------\n\nCo-authored-by: flpereir \u003cfabio.carneiro@cern.ch\u003e\nCo-authored-by: kwenzh \u003cyukunzhang29@hotmail.com\u003e"
    },
    {
      "commit": "bd70a0859b9d739aad0547aa61bd17291049773b",
      "tree": "dbc973a40d13c516ec945e546a30bf19df0ae4d0",
      "parents": [
        "f433b701e2f8b224e5ac187fd1004048ee9a9517"
      ],
      "author": {
        "name": "dependabot[bot]",
        "email": "49699333+dependabot[bot]@users.noreply.github.com",
        "time": "Mon Jun 01 10:04:34 2026 +0200"
      },
      "committer": {
        "name": "GitHub",
        "email": "noreply@github.com",
        "time": "Mon Jun 01 10:04:34 2026 +0200"
      },
      "message": "Bump org.apache.maven.plugins:maven-surefire-plugin in /lang/java (#3805)\n\nBumps [org.apache.maven.plugins:maven-surefire-plugin](https://github.com/apache/maven-surefire) from 3.5.5 to 3.5.6.\n- [Release notes](https://github.com/apache/maven-surefire/releases)\n- [Commits](https://github.com/apache/maven-surefire/compare/surefire-3.5.5...surefire-3.5.6)\n\n---\nupdated-dependencies:\n- dependency-name: org.apache.maven.plugins:maven-surefire-plugin\n  dependency-version: 3.5.6\n  dependency-type: direct:production\n  update-type: version-update:semver-patch\n...\n\nSigned-off-by: dependabot[bot] \u003csupport@github.com\u003e\nCo-authored-by: dependabot[bot] \u003c49699333+dependabot[bot]@users.noreply.github.com\u003e"
    },
    {
      "commit": "f433b701e2f8b224e5ac187fd1004048ee9a9517",
      "tree": "1af0b3e89370c50ae733008c18d7ab07c4154d8d",
      "parents": [
        "2fb95289d49cd5786062c76ed94115525f211ba6"
      ],
      "author": {
        "name": "dependabot[bot]",
        "email": "49699333+dependabot[bot]@users.noreply.github.com",
        "time": "Mon Jun 01 10:04:24 2026 +0200"
      },
      "committer": {
        "name": "GitHub",
        "email": "noreply@github.com",
        "time": "Mon Jun 01 10:04:24 2026 +0200"
      },
      "message": "Bump tmp from 0.2.6 to 0.2.7 in /lang/js (#3803)\n\nBumps [tmp](https://github.com/raszi/node-tmp) from 0.2.6 to 0.2.7.\n- [Changelog](https://github.com/raszi/node-tmp/blob/master/CHANGELOG.md)\n- [Commits](https://github.com/raszi/node-tmp/compare/v0.2.6...v0.2.7)\n\n---\nupdated-dependencies:\n- dependency-name: tmp\n  dependency-version: 0.2.7\n  dependency-type: direct:development\n  update-type: version-update:semver-patch\n...\n\nSigned-off-by: dependabot[bot] \u003csupport@github.com\u003e\nCo-authored-by: dependabot[bot] \u003c49699333+dependabot[bot]@users.noreply.github.com\u003e"
    },
    {
      "commit": "2fb95289d49cd5786062c76ed94115525f211ba6",
      "tree": "05d035aeaa4292771c7e5cf7580390fb351ec4c5",
      "parents": [
        "5481629ae7be942436951bb0b0e7f23130e66e3e"
      ],
      "author": {
        "name": "dependabot[bot]",
        "email": "49699333+dependabot[bot]@users.noreply.github.com",
        "time": "Mon Jun 01 10:04:13 2026 +0200"
      },
      "committer": {
        "name": "GitHub",
        "email": "noreply@github.com",
        "time": "Mon Jun 01 10:04:13 2026 +0200"
      },
      "message": "Bump coverlet.msbuild from 10.0.0 to 10.0.1 (#3798)\n\n---\nupdated-dependencies:\n- dependency-name: coverlet.msbuild\n  dependency-version: 10.0.1\n  dependency-type: direct:production\n  update-type: version-update:semver-patch\n...\n\nSigned-off-by: dependabot[bot] \u003csupport@github.com\u003e\nCo-authored-by: dependabot[bot] \u003c49699333+dependabot[bot]@users.noreply.github.com\u003e"
    },
    {
      "commit": "5481629ae7be942436951bb0b0e7f23130e66e3e",
      "tree": "38d7e4de01e05ceefe767e018cb5ffc41106e21b",
      "parents": [
        "b86ddf04ed951f4988d64f23daab66e5f7fca729"
      ],
      "author": {
        "name": "dependabot[bot]",
        "email": "49699333+dependabot[bot]@users.noreply.github.com",
        "time": "Mon Jun 01 09:19:33 2026 +0200"
      },
      "committer": {
        "name": "GitHub",
        "email": "noreply@github.com",
        "time": "Mon Jun 01 09:19:33 2026 +0200"
      },
      "message": "Bump com.fasterxml.jackson:jackson-bom in /lang/java (#3804)\n\nBumps [com.fasterxml.jackson:jackson-bom](https://github.com/FasterXML/jackson-bom) from 2.21.3 to 2.21.4.\n- [Commits](https://github.com/FasterXML/jackson-bom/compare/jackson-bom-2.21.3...jackson-bom-2.21.4)\n\n---\nupdated-dependencies:\n- dependency-name: com.fasterxml.jackson:jackson-bom\n  dependency-version: 2.21.4\n  dependency-type: direct:production\n  update-type: version-update:semver-patch\n...\n\nSigned-off-by: dependabot[bot] \u003csupport@github.com\u003e\nCo-authored-by: dependabot[bot] \u003c49699333+dependabot[bot]@users.noreply.github.com\u003e"
    },
    {
      "commit": "b86ddf04ed951f4988d64f23daab66e5f7fca729",
      "tree": "95b5dca6424877a00a16af923557d318da68f3a7",
      "parents": [
        "6db0de27609e7a2b76934be8cbb3a807f576f882"
      ],
      "author": {
        "name": "dependabot[bot]",
        "email": "49699333+dependabot[bot]@users.noreply.github.com",
        "time": "Mon Jun 01 09:19:20 2026 +0200"
      },
      "committer": {
        "name": "GitHub",
        "email": "noreply@github.com",
        "time": "Mon Jun 01 09:19:20 2026 +0200"
      },
      "message": "Bump com.diffplug.spotless:spotless-maven-plugin in /lang/java (#3802)\n\nBumps [com.diffplug.spotless:spotless-maven-plugin](https://github.com/diffplug/spotless) from 3.5.1 to 3.6.0.\n- [Release notes](https://github.com/diffplug/spotless/releases)\n- [Changelog](https://github.com/diffplug/spotless/blob/main/CHANGES.md)\n- [Commits](https://github.com/diffplug/spotless/compare/maven/3.5.1...maven/3.6.0)\n\n---\nupdated-dependencies:\n- dependency-name: com.diffplug.spotless:spotless-maven-plugin\n  dependency-version: 3.6.0\n  dependency-type: direct:production\n  update-type: version-update:semver-minor\n...\n\nSigned-off-by: dependabot[bot] \u003csupport@github.com\u003e\nCo-authored-by: dependabot[bot] \u003c49699333+dependabot[bot]@users.noreply.github.com\u003e"
    },
    {
      "commit": "6db0de27609e7a2b76934be8cbb3a807f576f882",
      "tree": "3293cd75399ff88940481a84fedc9b94994f8a79",
      "parents": [
        "1259420f2706bedd5310bf31a67676af3f8e840a"
      ],
      "author": {
        "name": "dependabot[bot]",
        "email": "49699333+dependabot[bot]@users.noreply.github.com",
        "time": "Mon Jun 01 09:19:08 2026 +0200"
      },
      "committer": {
        "name": "GitHub",
        "email": "noreply@github.com",
        "time": "Mon Jun 01 09:19:08 2026 +0200"
      },
      "message": "Bump tmp from 0.2.5 to 0.2.6 in /lang/js (#3801)\n\nBumps [tmp](https://github.com/raszi/node-tmp) from 0.2.5 to 0.2.6.\n- [Changelog](https://github.com/raszi/node-tmp/blob/master/CHANGELOG.md)\n- [Commits](https://github.com/raszi/node-tmp/compare/v0.2.5...v0.2.6)\n\n---\nupdated-dependencies:\n- dependency-name: tmp\n  dependency-version: 0.2.6\n  dependency-type: direct:development\n...\n\nSigned-off-by: dependabot[bot] \u003csupport@github.com\u003e\nCo-authored-by: dependabot[bot] \u003c49699333+dependabot[bot]@users.noreply.github.com\u003e"
    },
    {
      "commit": "1259420f2706bedd5310bf31a67676af3f8e840a",
      "tree": "7fcdaf0df9a55ddd9b5fe4e556877b4bc6acc868",
      "parents": [
        "9c3010ffb9c9b5d370ad048d576d33d94b5f0257"
      ],
      "author": {
        "name": "dependabot[bot]",
        "email": "49699333+dependabot[bot]@users.noreply.github.com",
        "time": "Mon Jun 01 09:18:38 2026 +0200"
      },
      "committer": {
        "name": "GitHub",
        "email": "noreply@github.com",
        "time": "Mon Jun 01 09:18:38 2026 +0200"
      },
      "message": "Bump coverlet.collector from 10.0.0 to 10.0.1 (#3797)\n\n---\nupdated-dependencies:\n- dependency-name: coverlet.collector\n  dependency-version: 10.0.1\n  dependency-type: direct:production\n  update-type: version-update:semver-patch\n...\n\nSigned-off-by: dependabot[bot] \u003csupport@github.com\u003e\nCo-authored-by: dependabot[bot] \u003c49699333+dependabot[bot]@users.noreply.github.com\u003e"
    },
    {
      "commit": "9c3010ffb9c9b5d370ad048d576d33d94b5f0257",
      "tree": "679a8505f770e0fe2e82708a0130e8ef2d23b338",
      "parents": [
        "77d5c7f09d50f94a43d29710f26b2726165aec3a"
      ],
      "author": {
        "name": "dependabot[bot]",
        "email": "49699333+dependabot[bot]@users.noreply.github.com",
        "time": "Mon Jun 01 09:18:28 2026 +0200"
      },
      "committer": {
        "name": "GitHub",
        "email": "noreply@github.com",
        "time": "Mon Jun 01 09:18:28 2026 +0200"
      },
      "message": "Bump com.google.protobuf:protobuf-java in /lang/java (#3796)\n\nBumps [com.google.protobuf:protobuf-java](https://github.com/protocolbuffers/protobuf) from 4.34.1 to 4.35.0.\n- [Release notes](https://github.com/protocolbuffers/protobuf/releases)\n- [Commits](https://github.com/protocolbuffers/protobuf/commits)\n\n---\nupdated-dependencies:\n- dependency-name: com.google.protobuf:protobuf-java\n  dependency-version: 4.35.0\n  dependency-type: direct:production\n  update-type: version-update:semver-minor\n...\n\nSigned-off-by: dependabot[bot] \u003csupport@github.com\u003e\nCo-authored-by: dependabot[bot] \u003c49699333+dependabot[bot]@users.noreply.github.com\u003e"
    },
    {
      "commit": "77d5c7f09d50f94a43d29710f26b2726165aec3a",
      "tree": "bae124b93dab67b139c0745ce64c1909b7512ca4",
      "parents": [
        "65ca0a2a2df61cedf7fa070fd45a33d94108ac68"
      ],
      "author": {
        "name": "dependabot[bot]",
        "email": "49699333+dependabot[bot]@users.noreply.github.com",
        "time": "Mon Jun 01 08:50:32 2026 +0200"
      },
      "committer": {
        "name": "GitHub",
        "email": "noreply@github.com",
        "time": "Mon Jun 01 08:50:32 2026 +0200"
      },
      "message": "Bump com.github.luben:zstd-jni from 1.5.7-8 to 1.5.7-9 in /lang/java (#3795)\n\nBumps [com.github.luben:zstd-jni](https://github.com/luben/zstd-jni) from 1.5.7-8 to 1.5.7-9.\n- [Commits](https://github.com/luben/zstd-jni/compare/v1.5.7-8...v1.5.7-9)\n\n---\nupdated-dependencies:\n- dependency-name: com.github.luben:zstd-jni\n  dependency-version: 1.5.7-9\n  dependency-type: direct:production\n  update-type: version-update:semver-patch\n...\n\nSigned-off-by: dependabot[bot] \u003csupport@github.com\u003e\nCo-authored-by: dependabot[bot] \u003c49699333+dependabot[bot]@users.noreply.github.com\u003e"
    },
    {
      "commit": "65ca0a2a2df61cedf7fa070fd45a33d94108ac68",
      "tree": "7f2694a34929526899a7b0b8ed748837cb9e1b62",
      "parents": [
        "f9689b9347aea998918788f8e2a58710fe969462"
      ],
      "author": {
        "name": "dependabot[bot]",
        "email": "49699333+dependabot[bot]@users.noreply.github.com",
        "time": "Mon Jun 01 08:50:23 2026 +0200"
      },
      "committer": {
        "name": "GitHub",
        "email": "noreply@github.com",
        "time": "Mon Jun 01 08:50:23 2026 +0200"
      },
      "message": "Bump mocha from 11.7.5 to 11.7.6 in /lang/js (#3794)\n\nBumps [mocha](https://github.com/mochajs/mocha) from 11.7.5 to 11.7.6.\n- [Release notes](https://github.com/mochajs/mocha/releases)\n- [Changelog](https://github.com/mochajs/mocha/blob/v11.7.6/CHANGELOG.md)\n- [Commits](https://github.com/mochajs/mocha/compare/v11.7.5...v11.7.6)\n\n---\nupdated-dependencies:\n- dependency-name: mocha\n  dependency-version: 11.7.6\n  dependency-type: direct:development\n  update-type: version-update:semver-patch\n...\n\nSigned-off-by: dependabot[bot] \u003csupport@github.com\u003e\nCo-authored-by: dependabot[bot] \u003c49699333+dependabot[bot]@users.noreply.github.com\u003e"
    },
    {
      "commit": "f9689b9347aea998918788f8e2a58710fe969462",
      "tree": "fc12dcd80f419c69158091455dda6debfec7cbe9",
      "parents": [
        "5a6148c4c45f788cbaf7669c0e9123529c1c246a"
      ],
      "author": {
        "name": "dependabot[bot]",
        "email": "49699333+dependabot[bot]@users.noreply.github.com",
        "time": "Mon Jun 01 08:50:15 2026 +0200"
      },
      "committer": {
        "name": "GitHub",
        "email": "noreply@github.com",
        "time": "Mon Jun 01 08:50:15 2026 +0200"
      },
      "message": "Bump org.apache.maven.plugins:maven-enforcer-plugin in /lang/java (#3793)\n\nBumps [org.apache.maven.plugins:maven-enforcer-plugin](https://github.com/apache/maven-enforcer) from 3.6.2 to 3.6.3.\n- [Release notes](https://github.com/apache/maven-enforcer/releases)\n- [Commits](https://github.com/apache/maven-enforcer/compare/enforcer-3.6.2...enforcer-3.6.3)\n\n---\nupdated-dependencies:\n- dependency-name: org.apache.maven.plugins:maven-enforcer-plugin\n  dependency-version: 3.6.3\n  dependency-type: direct:production\n  update-type: version-update:semver-patch\n...\n\nSigned-off-by: dependabot[bot] \u003csupport@github.com\u003e\nCo-authored-by: dependabot[bot] \u003c49699333+dependabot[bot]@users.noreply.github.com\u003e"
    },
    {
      "commit": "5a6148c4c45f788cbaf7669c0e9123529c1c246a",
      "tree": "8c14d9fe56771cddda94c29ea76ca46ad1dc4755",
      "parents": [
        "c3c14fa184a9dbe11c9367effbc563ea7852c274"
      ],
      "author": {
        "name": "dependabot[bot]",
        "email": "49699333+dependabot[bot]@users.noreply.github.com",
        "time": "Mon Jun 01 08:50:05 2026 +0200"
      },
      "committer": {
        "name": "GitHub",
        "email": "noreply@github.com",
        "time": "Mon Jun 01 08:50:05 2026 +0200"
      },
      "message": "Bump postcss from 8.5.14 to 8.5.15 in /doc (#3792)\n\nBumps [postcss](https://github.com/postcss/postcss) from 8.5.14 to 8.5.15.\n- [Release notes](https://github.com/postcss/postcss/releases)\n- [Changelog](https://github.com/postcss/postcss/blob/main/CHANGELOG.md)\n- [Commits](https://github.com/postcss/postcss/compare/8.5.14...8.5.15)\n\n---\nupdated-dependencies:\n- dependency-name: postcss\n  dependency-version: 8.5.15\n  dependency-type: direct:development\n  update-type: version-update:semver-patch\n...\n\nSigned-off-by: dependabot[bot] \u003csupport@github.com\u003e\nCo-authored-by: dependabot[bot] \u003c49699333+dependabot[bot]@users.noreply.github.com\u003e"
    },
    {
      "commit": "c3c14fa184a9dbe11c9367effbc563ea7852c274",
      "tree": "0044a723d26a86baf5fb59cbb2a9bc2e74cb777d",
      "parents": [
        "66e29f38608e987e96e27f5e06c27eb0f61bd24f"
      ],
      "author": {
        "name": "dependabot[bot]",
        "email": "49699333+dependabot[bot]@users.noreply.github.com",
        "time": "Mon Jun 01 08:49:53 2026 +0200"
      },
      "committer": {
        "name": "GitHub",
        "email": "noreply@github.com",
        "time": "Mon Jun 01 08:49:53 2026 +0200"
      },
      "message": "Bump io.netty:netty-bom from 4.2.13.Final to 4.2.14.Final in /lang/java (#3791)\n\nBumps [io.netty:netty-bom](https://github.com/netty/netty) from 4.2.13.Final to 4.2.14.Final.\n- [Release notes](https://github.com/netty/netty/releases)\n- [Commits](https://github.com/netty/netty/compare/netty-4.2.13.Final...netty-4.2.14.Final)\n\n---\nupdated-dependencies:\n- dependency-name: io.netty:netty-bom\n  dependency-version: 4.2.14.Final\n  dependency-type: direct:production\n  update-type: version-update:semver-patch\n...\n\nSigned-off-by: dependabot[bot] \u003csupport@github.com\u003e\nCo-authored-by: dependabot[bot] \u003c49699333+dependabot[bot]@users.noreply.github.com\u003e"
    },
    {
      "commit": "66e29f38608e987e96e27f5e06c27eb0f61bd24f",
      "tree": "31464ed42e097fb0e7c39db1192765e5d1943118",
      "parents": [
        "9ce6b208a69ec74a4b070e27d8917b98705a6924"
      ],
      "author": {
        "name": "Gang Wu",
        "email": "ustcwg@gmail.com",
        "time": "Wed May 27 19:59:48 2026 +0800"
      },
      "committer": {
        "name": "GitHub",
        "email": "noreply@github.com",
        "time": "Wed May 27 14:59:48 2026 +0300"
      },
      "message": "AVRO-4260: [C++] Upgrade minimum C++ standard from C++17 to C++20 (#3800)\n\nRaise CMAKE_CXX_STANDARD default from 17 to 20 and update the\nminimum version check accordingly."
    },
    {
      "commit": "9ce6b208a69ec74a4b070e27d8917b98705a6924",
      "tree": "204b35355fb52fe143802c0e80c6377538a29aa4",
      "parents": [
        "0cde4852b7361bb1674d987fabfa4022672dc516"
      ],
      "author": {
        "name": "dependabot[bot]",
        "email": "49699333+dependabot[bot]@users.noreply.github.com",
        "time": "Thu May 21 20:48:01 2026 +0200"
      },
      "committer": {
        "name": "GitHub",
        "email": "noreply@github.com",
        "time": "Thu May 21 20:48:01 2026 +0200"
      },
      "message": "Bump idna from 3.11 to 3.15 in /lang/py (#3787)\n\nBumps [idna](https://github.com/kjd/idna) from 3.11 to 3.15.\n- [Release notes](https://github.com/kjd/idna/releases)\n- [Changelog](https://github.com/kjd/idna/blob/master/HISTORY.md)\n- [Commits](https://github.com/kjd/idna/compare/v3.11...v3.15)\n\n---\nupdated-dependencies:\n- dependency-name: idna\n  dependency-version: \u00273.15\u0027\n  dependency-type: indirect\n...\n\nSigned-off-by: dependabot[bot] \u003csupport@github.com\u003e\nCo-authored-by: dependabot[bot] \u003c49699333+dependabot[bot]@users.noreply.github.com\u003e"
    },
    {
      "commit": "0cde4852b7361bb1674d987fabfa4022672dc516",
      "tree": "47159674802a10bf4792b3bcc736a652807ff44a",
      "parents": [
        "a76fb29669cd44a275db98ce8fc9b50af383d997"
      ],
      "author": {
        "name": "dependabot[bot]",
        "email": "49699333+dependabot[bot]@users.noreply.github.com",
        "time": "Thu May 21 20:47:38 2026 +0200"
      },
      "committer": {
        "name": "GitHub",
        "email": "noreply@github.com",
        "time": "Thu May 21 20:47:38 2026 +0200"
      },
      "message": "Bump System.CodeDom from 10.0.7 to 10.0.8 (#3786)\n\n---\nupdated-dependencies:\n- dependency-name: System.CodeDom\n  dependency-version: 10.0.8\n  dependency-type: direct:production\n  update-type: version-update:semver-patch\n...\n\nSigned-off-by: dependabot[bot] \u003csupport@github.com\u003e\nCo-authored-by: dependabot[bot] \u003c49699333+dependabot[bot]@users.noreply.github.com\u003e"
    },
    {
      "commit": "a76fb29669cd44a275db98ce8fc9b50af383d997",
      "tree": "0dfa19a9b263718964de87a579db5adbe8ce78bb",
      "parents": [
        "61b4e7413222610a6d1f7aace255d3418afb69bd"
      ],
      "author": {
        "name": "dependabot[bot]",
        "email": "49699333+dependabot[bot]@users.noreply.github.com",
        "time": "Thu May 21 20:47:09 2026 +0200"
      },
      "committer": {
        "name": "GitHub",
        "email": "noreply@github.com",
        "time": "Thu May 21 20:47:09 2026 +0200"
      },
      "message": "Bump Microsoft.Build.Framework and Microsoft.Build.Utilities.Core (#3785)\n\nBumps Microsoft.Build.Framework from 18.4.0 to 18.6.3\nBumps Microsoft.Build.Utilities.Core from 18.4.0 to 18.6.3\n\n---\nupdated-dependencies:\n- dependency-name: Microsoft.Build.Framework\n  dependency-version: 18.6.3\n  dependency-type: direct:production\n  update-type: version-update:semver-minor\n- dependency-name: Microsoft.Build.Utilities.Core\n  dependency-version: 18.6.3\n  dependency-type: direct:production\n  update-type: version-update:semver-minor\n...\n\nSigned-off-by: dependabot[bot] \u003csupport@github.com\u003e\nCo-authored-by: dependabot[bot] \u003c49699333+dependabot[bot]@users.noreply.github.com\u003e"
    },
    {
      "commit": "61b4e7413222610a6d1f7aace255d3418afb69bd",
      "tree": "e88db0a4a6bcb64c5c10c63c2161026cf660c27c",
      "parents": [
        "8b2f4a129ce79f9c8c66e6526d654784cd8b7e0f"
      ],
      "author": {
        "name": "dependabot[bot]",
        "email": "49699333+dependabot[bot]@users.noreply.github.com",
        "time": "Thu May 21 20:46:35 2026 +0200"
      },
      "committer": {
        "name": "GitHub",
        "email": "noreply@github.com",
        "time": "Thu May 21 20:46:35 2026 +0200"
      },
      "message": "Update mypy requirement from \u003c2.1.0 to \u003c2.2.0 in /lang/py (#3783)\n\nUpdates the requirements on [mypy](https://github.com/python/mypy) to permit the latest version.\n- [Changelog](https://github.com/python/mypy/blob/master/CHANGELOG.md)\n- [Commits](https://github.com/python/mypy/compare/v0.1.0...v2.1.0)\n\n---\nupdated-dependencies:\n- dependency-name: mypy\n  dependency-version: 2.1.0\n  dependency-type: direct:development\n...\n\nSigned-off-by: dependabot[bot] \u003csupport@github.com\u003e\nCo-authored-by: dependabot[bot] \u003c49699333+dependabot[bot]@users.noreply.github.com\u003e"
    },
    {
      "commit": "8b2f4a129ce79f9c8c66e6526d654784cd8b7e0f",
      "tree": "3a7bf3442a11ddff24695ac90207e4dd94e9c146",
      "parents": [
        "7f1bccdb51452430acf8d895a21de0a7f19a2eb7"
      ],
      "author": {
        "name": "dependabot[bot]",
        "email": "49699333+dependabot[bot]@users.noreply.github.com",
        "time": "Thu May 21 20:46:22 2026 +0200"
      },
      "committer": {
        "name": "GitHub",
        "email": "noreply@github.com",
        "time": "Thu May 21 20:46:22 2026 +0200"
      },
      "message": "Bump slf4j.version from 2.0.17 to 2.0.18 in /lang/java (#3782)\n\nBumps `slf4j.version` from 2.0.17 to 2.0.18.\n\nUpdates `org.slf4j:slf4j-api` from 2.0.17 to 2.0.18\n\nUpdates `org.slf4j:slf4j-simple` from 2.0.17 to 2.0.18\n\nUpdates `org.slf4j:slf4j-log4j12` from 2.0.17 to 2.0.18\n\n---\nupdated-dependencies:\n- dependency-name: org.slf4j:slf4j-api\n  dependency-version: 2.0.18\n  dependency-type: direct:production\n  update-type: version-update:semver-patch\n- dependency-name: org.slf4j:slf4j-simple\n  dependency-version: 2.0.18\n  dependency-type: direct:development\n  update-type: version-update:semver-patch\n- dependency-name: org.slf4j:slf4j-log4j12\n  dependency-version: 2.0.18\n  dependency-type: direct:production\n  update-type: version-update:semver-patch\n...\n\nSigned-off-by: dependabot[bot] \u003csupport@github.com\u003e\nCo-authored-by: dependabot[bot] \u003c49699333+dependabot[bot]@users.noreply.github.com\u003e"
    },
    {
      "commit": "7f1bccdb51452430acf8d895a21de0a7f19a2eb7",
      "tree": "de86799ca9a2e2c4c5e0eb65b3a5ae2fc45fc348",
      "parents": [
        "85d61282f514df9b93ce7f26998a3ed803eba87f"
      ],
      "author": {
        "name": "dependabot[bot]",
        "email": "49699333+dependabot[bot]@users.noreply.github.com",
        "time": "Thu May 21 20:45:41 2026 +0200"
      },
      "committer": {
        "name": "GitHub",
        "email": "noreply@github.com",
        "time": "Thu May 21 20:45:41 2026 +0200"
      },
      "message": "Bump com.diffplug.spotless:spotless-maven-plugin in /lang/java (#3781)\n\nBumps [com.diffplug.spotless:spotless-maven-plugin](https://github.com/diffplug/spotless) from 3.4.0 to 3.5.1.\n- [Release notes](https://github.com/diffplug/spotless/releases)\n- [Changelog](https://github.com/diffplug/spotless/blob/main/CHANGES.md)\n- [Commits](https://github.com/diffplug/spotless/compare/maven/3.4.0...maven/3.5.1)\n\n---\nupdated-dependencies:\n- dependency-name: com.diffplug.spotless:spotless-maven-plugin\n  dependency-version: 3.5.1\n  dependency-type: direct:production\n  update-type: version-update:semver-minor\n...\n\nSigned-off-by: dependabot[bot] \u003csupport@github.com\u003e\nCo-authored-by: dependabot[bot] \u003c49699333+dependabot[bot]@users.noreply.github.com\u003e"
    },
    {
      "commit": "85d61282f514df9b93ce7f26998a3ed803eba87f",
      "tree": "847f96b34ae44ce2d19eb6021949172227b7695d",
      "parents": [
        "68da8fb99da5c482f17853e01e79f714e3717b42"
      ],
      "author": {
        "name": "The Apache Software Foundation",
        "email": "root-asf-gitbox-commits@apache.org",
        "time": "Mon May 18 12:18:35 2026 -0500"
      },
      "committer": {
        "name": "GitHub",
        "email": "noreply@github.com",
        "time": "Mon May 18 19:18:35 2026 +0200"
      },
      "message": "Set up default protection ruleset for default and release branches (#3780)"
    },
    {
      "commit": "68da8fb99da5c482f17853e01e79f714e3717b42",
      "tree": "160f8c89aca1bfeacaedad28cfcbf998bc590f54",
      "parents": [
        "dd72feaa762e78a5c9032b78d405bf2998a0c7c2"
      ],
      "author": {
        "name": "Mattia Basone",
        "email": "mattia.basone@gmail.com",
        "time": "Sat May 16 09:21:20 2026 +0200"
      },
      "committer": {
        "name": "GitHub",
        "email": "noreply@github.com",
        "time": "Sat May 16 10:21:20 2026 +0300"
      },
      "message": "bump composer version (#3779)"
    },
    {
      "commit": "dd72feaa762e78a5c9032b78d405bf2998a0c7c2",
      "tree": "1e2d73213b6853640f3bf9b4463a52936d169e54",
      "parents": [
        "22f53c8c15e575165abdcd21f6f48efcdd4a33cd"
      ],
      "author": {
        "name": "Oscar Westra van Holthe - Kind",
        "email": "822992+opwvhk@users.noreply.github.com",
        "time": "Fri May 15 19:06:52 2026 +0200"
      },
      "committer": {
        "name": "GitHub",
        "email": "noreply@github.com",
        "time": "Fri May 15 19:06:52 2026 +0200"
      },
      "message": "AVRO-4257: use the new SchemaParser (#3766)\n\n* AVRO-4257: Add convenience methods to SchemaParser\n\n* AVRO-4257: Use the new schema parser everywhere\n\nUses the String convenience parsing method where possible, and the\n(non-validating, JSON only) internal parser where appropriate."
    },
    {
      "commit": "22f53c8c15e575165abdcd21f6f48efcdd4a33cd",
      "tree": "274b31607781f56705b55486beaded73147686d1",
      "parents": [
        "34bdcf98ab5d0639219f4d1ec144828e0bfa58fe"
      ],
      "author": {
        "name": "Oscar Westra van Holthe - Kind",
        "email": "822992+opwvhk@users.noreply.github.com",
        "time": "Fri May 15 18:55:28 2026 +0200"
      },
      "committer": {
        "name": "GitHub",
        "email": "noreply@github.com",
        "time": "Fri May 15 18:55:28 2026 +0200"
      },
      "message": "AVRO-4176: Java parser allows field type to be object with custom type (#3772)\n\n* AVRO-4176: Disallow named type alteration\n\nThe test cases for self reference unions contained a bug that seemed to\nmake the parsing bug necessary.\n\n* AVRO-4176: Add test"
    },
    {
      "commit": "34bdcf98ab5d0639219f4d1ec144828e0bfa58fe",
      "tree": "046fafc506c33de8296a4d3f9dfbb5c78953eb4f",
      "parents": [
        "4c29cfb234c6ca0d9df8a572ca04b65ccc7c21e4"
      ],
      "author": {
        "name": "Oscar Westra van Holthe - Kind",
        "email": "822992+opwvhk@users.noreply.github.com",
        "time": "Fri May 15 18:55:10 2026 +0200"
      },
      "committer": {
        "name": "GitHub",
        "email": "noreply@github.com",
        "time": "Fri May 15 18:55:10 2026 +0200"
      },
      "message": "AVRO-4182: Avoid ANTLR parsing edge cases (#3756)\n\nIn some cases, enter and exit rules are not called in pairs while parsing.\nApparently, this is by design. This fix adds a test that the fix does indeed\nwork (it tests an exception, as the error does not show up with a duplicated\ndefinition).\n\nNote: this change keeps the entire parse tree in memory during parsing,\nand allows it to be collected directly afterwards."
    },
    {
      "commit": "4c29cfb234c6ca0d9df8a572ca04b65ccc7c21e4",
      "tree": "186a2805de9564e0f1dffe5017606f9bdb215205",
      "parents": [
        "d28279dace6ffd2deaf6a66e5e82f81a582c3252"
      ],
      "author": {
        "name": "zakpayne8283",
        "email": "zakpayne8283@gmail.com",
        "time": "Mon May 11 14:55:41 2026 -0400"
      },
      "committer": {
        "name": "GitHub",
        "email": "noreply@github.com",
        "time": "Mon May 11 20:55:41 2026 +0200"
      },
      "message": "AVRO-4211: Java fix schema generation for union fields with default value that isn\u0027t the first union element (#3709)"
    },
    {
      "commit": "d28279dace6ffd2deaf6a66e5e82f81a582c3252",
      "tree": "8c329c49abf00b664e13910f498a617ee3770b1e",
      "parents": [
        "4502c1ba1c453702fd26966a5e5c10441e0d1384"
      ],
      "author": {
        "name": "Steve Loughran",
        "email": "stevel@apache.org",
        "time": "Mon May 11 19:45:20 2026 +0100"
      },
      "committer": {
        "name": "GitHub",
        "email": "noreply@github.com",
        "time": "Mon May 11 20:45:20 2026 +0200"
      },
      "message": "AVRO-4247: Enforce decompression size limits (#3745)\n\n* [AVRO-4081] Add decompression size limit to prevent decompression bomb DoS\n\nAdd maximum decompression size limit in DeflateCodec to prevent\nOutOfMemoryError when processing maliciously crafted Avro files\nwith high compression ratios (decompression bombs).\n\nThe limit defaults to 200MB and can be configured via system property:\norg.apache.avro.limits.decompress.maxLength\n\n* Update lang/java/avro/src/main/java/org/apache/avro/file/DeflateCodec.java\r\n\r\nThanks!\n\nCo-authored-by: Martin Grigorov \u003cmartin-g@users.noreply.github.com\u003e\n\n* Update lang/java/avro/src/main/java/org/apache/avro/file/DeflateCodec.java\n\nCo-authored-by: Martin Grigorov \u003cmartin-g@users.noreply.github.com\u003e\n\n* Address code review feedback for decompression bomb fix\n\n- Move MAX_DECOMPRESS_LENGTH initialization to static block (read once at class load)\n- Add WARNING log for invalid property values (NumberFormatException)\n- Validate negative and zero values, reject with warning\n- Add \"(bytes)\" to error message for clarity\n- Add quotes around property name in error message\n\nTest command:\njava -Xmx64m -Dorg.apache.avro.limits.decompress.maxLength\u003d1048576 \\\n  -jar avro-tools-1.13.0-SNAPSHOT.jar tojson poc.avro\n\nExpected behavior:\nException in thread \"main\" org.apache.avro.AvroRuntimeException:\nDecompressed size 1056768 (bytes) exceeds maximum allowed size 1048576.\nThis can be configured by setting the system property \u0027org.apache.avro.limits.decompress.maxLength\u0027\n\n* [AVRO-4] Move limit checks into NonCopyingByteArrayOutputStream\n\n* Automatically available to all codecs\n* Does need an explicit constructor with no limit, used in DataFileWriter\n* No tests, though that new constructor makes it trivial\n\nNote: merged in main as DataFileWriter changes would otherwise stop merging\nChange-Id: Ifc5b8921a00425df331a4889472b3e78c6677bde\n\n* [AVRO-4247] review feedback\n\n* Tests\n* Option read moved to SystemLimitException\n\nChange-Id: I01d4203ad65e0e09dde88b33f603879323b06425\n\n* [AVRO-4247] Rework invocation\n\n* NonCopyingByteArrayOutputStream ctor reverts to unlimited\n* moved the check logic to SystemLimitException\n* new static method restrictedCapacityOutputStream() is invoked to\n  get capacity limited streams\n* All Codecs use this\n* Except Snappy which calls the SystemLimitException check directly\n* And there\u0027s a test for that too\n\nChange-Id: I0aa355e258c03d452c4e5a4a18605e8e2b357b2d\n\n* spotless\n\nChange-Id: Ie76e91f9e00ff799d2c0d82258802e6a7f4ef756\n\n* getLongLimitFromProperty() to use parameters over inline constants\n\nChange-Id: I5905dac4ac8a9f838cd7b3025906ef278a5cfb58\n\n* change static factory method to \"capacityLimitedOutputStream()\"\n\nChange-Id: I24dcd2a023c544370c347bdcd17e6d68abeaf260\n\n* Apply compressor changes from iemejia\n\n+ limit the size of a single output stream to max memory/4.\n\nChange-Id: I0344e4c586f982f37eead7d4a6246bd1af5b4e81\n\n* Beautify with spotless\n\n---------\n\nCo-authored-by: OwenSanzas \u003czesheng@tamu.edu\u003e\nCo-authored-by: Ze Sheng \u003c108382772+OwenSanzas@users.noreply.github.com\u003e\nCo-authored-by: Martin Grigorov \u003cmartin-g@users.noreply.github.com\u003e\nCo-authored-by: Ryan Skraba \u003cryan.skraba@aiven.io\u003e"
    },
    {
      "commit": "4502c1ba1c453702fd26966a5e5c10441e0d1384",
      "tree": "1d4c7eff3f73a113deff1144dbf4546fa09487fa",
      "parents": [
        "e1894b397b1d86c398165a8d31e1a58114498e28"
      ],
      "author": {
        "name": "Ryan Skraba",
        "email": "ryan@skraba.com",
        "time": "Mon May 11 20:41:21 2026 +0200"
      },
      "committer": {
        "name": "GitHub",
        "email": "noreply@github.com",
        "time": "Mon May 11 20:41:21 2026 +0200"
      },
      "message": "AVRO-4209: [java] Reflect correctly on recursive schemas (#3765)\n\n* AVRO-4209: [java] Reflect correctly on recursive schemas\n\n* Fix CodeQL / Inconsistent equals and hashCode\n\n---------\n\nCo-authored-by: Oscar Westra van Holthe - Kind \u003c822992+opwvhk@users.noreply.github.com\u003e"
    },
    {
      "commit": "e1894b397b1d86c398165a8d31e1a58114498e28",
      "tree": "ca0779b89ff9d55fba7e2fb8b158091420c87cc8",
      "parents": [
        "d3072c20b9e38a9c0ceb11009eadfb2a8e420583"
      ],
      "author": {
        "name": "dependabot[bot]",
        "email": "49699333+dependabot[bot]@users.noreply.github.com",
        "time": "Mon May 11 20:38:50 2026 +0200"
      },
      "committer": {
        "name": "GitHub",
        "email": "noreply@github.com",
        "time": "Mon May 11 20:38:50 2026 +0200"
      },
      "message": "Bump urllib3 from 2.6.3 to 2.7.0 in /lang/py (#3775)\n\nBumps [urllib3](https://github.com/urllib3/urllib3) from 2.6.3 to 2.7.0.\n- [Release notes](https://github.com/urllib3/urllib3/releases)\n- [Changelog](https://github.com/urllib3/urllib3/blob/main/CHANGES.rst)\n- [Commits](https://github.com/urllib3/urllib3/compare/2.6.3...2.7.0)\n\n---\nupdated-dependencies:\n- dependency-name: urllib3\n  dependency-version: 2.7.0\n  dependency-type: indirect\n...\n\nSigned-off-by: dependabot[bot] \u003csupport@github.com\u003e\nCo-authored-by: dependabot[bot] \u003c49699333+dependabot[bot]@users.noreply.github.com\u003e"
    },
    {
      "commit": "d3072c20b9e38a9c0ceb11009eadfb2a8e420583",
      "tree": "d3305ba959fb3ca8352990289a4b660b7043a134",
      "parents": [
        "fedc4929d6c6db5ace3485330240e8f7ebb49298"
      ],
      "author": {
        "name": "dependabot[bot]",
        "email": "49699333+dependabot[bot]@users.noreply.github.com",
        "time": "Mon May 11 17:15:59 2026 +0200"
      },
      "committer": {
        "name": "GitHub",
        "email": "noreply@github.com",
        "time": "Mon May 11 17:15:59 2026 +0200"
      },
      "message": "Bump postcss from 8.5.13 to 8.5.14 in /doc (#3768)\n\nBumps [postcss](https://github.com/postcss/postcss) from 8.5.13 to 8.5.14.\n- [Release notes](https://github.com/postcss/postcss/releases)\n- [Changelog](https://github.com/postcss/postcss/blob/main/CHANGELOG.md)\n- [Commits](https://github.com/postcss/postcss/compare/8.5.13...8.5.14)\n\n---\nupdated-dependencies:\n- dependency-name: postcss\n  dependency-version: 8.5.14\n  dependency-type: direct:development\n  update-type: version-update:semver-patch\n...\n\nSigned-off-by: dependabot[bot] \u003csupport@github.com\u003e\nCo-authored-by: dependabot[bot] \u003c49699333+dependabot[bot]@users.noreply.github.com\u003e"
    },
    {
      "commit": "fedc4929d6c6db5ace3485330240e8f7ebb49298",
      "tree": "625f18a9ad42cc5e1d9815937ba08a6a0108b496",
      "parents": [
        "4b25be3b0d4e36195881088a9d1c5522afbfabc8"
      ],
      "author": {
        "name": "dependabot[bot]",
        "email": "49699333+dependabot[bot]@users.noreply.github.com",
        "time": "Mon May 11 13:38:39 2026 +0200"
      },
      "committer": {
        "name": "GitHub",
        "email": "noreply@github.com",
        "time": "Mon May 11 13:38:39 2026 +0200"
      },
      "message": "Update mypy requirement from \u003c1.21.0 to \u003c2.1.0 in /lang/py (#3769)\n\nUpdates the requirements on [mypy](https://github.com/python/mypy) to permit the latest version.\n- [Changelog](https://github.com/python/mypy/blob/master/CHANGELOG.md)\n- [Commits](https://github.com/python/mypy/compare/v0.1.0...v2.0.0)\n\n---\nupdated-dependencies:\n- dependency-name: mypy\n  dependency-version: 2.0.0\n  dependency-type: direct:development\n...\n\nSigned-off-by: dependabot[bot] \u003csupport@github.com\u003e\nCo-authored-by: dependabot[bot] \u003c49699333+dependabot[bot]@users.noreply.github.com\u003e"
    },
    {
      "commit": "4b25be3b0d4e36195881088a9d1c5522afbfabc8",
      "tree": "73494eabd3329102912b4f0c999d95f26503d728",
      "parents": [
        "1461aaa11d88735a31e80c38e233b893d546005a"
      ],
      "author": {
        "name": "dependabot[bot]",
        "email": "49699333+dependabot[bot]@users.noreply.github.com",
        "time": "Mon May 11 13:37:14 2026 +0200"
      },
      "committer": {
        "name": "GitHub",
        "email": "noreply@github.com",
        "time": "Mon May 11 13:37:14 2026 +0200"
      },
      "message": "Bump io.netty:netty-bom from 4.2.12.Final to 4.2.13.Final in /lang/java (#3771)\n\nBumps [io.netty:netty-bom](https://github.com/netty/netty) from 4.2.12.Final to 4.2.13.Final.\n- [Release notes](https://github.com/netty/netty/releases)\n- [Commits](https://github.com/netty/netty/compare/netty-4.2.12.Final...netty-4.2.13.Final)\n\n---\nupdated-dependencies:\n- dependency-name: io.netty:netty-bom\n  dependency-version: 4.2.13.Final\n  dependency-type: direct:production\n  update-type: version-update:semver-patch\n...\n\nSigned-off-by: dependabot[bot] \u003csupport@github.com\u003e\nCo-authored-by: dependabot[bot] \u003c49699333+dependabot[bot]@users.noreply.github.com\u003e"
    },
    {
      "commit": "1461aaa11d88735a31e80c38e233b893d546005a",
      "tree": "475383feba23af6ddeba5cbfbfe538907460a59f",
      "parents": [
        "c5f66c7cb5f522f7c6fa7ce68e640e3833525d8a"
      ],
      "author": {
        "name": "dependabot[bot]",
        "email": "49699333+dependabot[bot]@users.noreply.github.com",
        "time": "Mon May 11 13:36:42 2026 +0200"
      },
      "committer": {
        "name": "GitHub",
        "email": "noreply@github.com",
        "time": "Mon May 11 13:36:42 2026 +0200"
      },
      "message": "Bump org.apache:apache from 37 to 38 in /lang/java (#3767)\n\nBumps [org.apache:apache](https://github.com/apache/maven-apache-parent) from 37 to 38.\n- [Release notes](https://github.com/apache/maven-apache-parent/releases)\n- [Commits](https://github.com/apache/maven-apache-parent/commits)\n\n---\nupdated-dependencies:\n- dependency-name: org.apache:apache\n  dependency-version: \u002738\u0027\n  dependency-type: direct:production\n  update-type: version-update:semver-major\n...\n\nSigned-off-by: dependabot[bot] \u003csupport@github.com\u003e\nCo-authored-by: dependabot[bot] \u003c49699333+dependabot[bot]@users.noreply.github.com\u003e"
    },
    {
      "commit": "c5f66c7cb5f522f7c6fa7ce68e640e3833525d8a",
      "tree": "74b019f6bafde06f95178382dd6af7f13130ee78",
      "parents": [
        "892d6997dcb65627560b04bd76c5a3dd97666cdf"
      ],
      "author": {
        "name": "RawScape",
        "email": "6241315+RawScape@users.noreply.github.com",
        "time": "Sun May 10 14:23:20 2026 +0200"
      },
      "committer": {
        "name": "GitHub",
        "email": "noreply@github.com",
        "time": "Sun May 10 14:23:20 2026 +0200"
      },
      "message": "AVRO-2825: [csharp] Resolve: C# Logical Types throw exception on unknown (#3727)\n\n* AVRO-2825: [csharp] Resolve: C# Logical Types throw exception on unknown logical type\n\n(cherry picked from commit ad61af02da435652ba0662d34205f60fa88537cb)\n\n* [AVRO-3941] CSharp Resolve missing namespace issue\n\n(cherry picked from commit e5a7dedf9959687637f621bfdecbe478a5a89cc4)\n\n* Resolve requested changes on PR 2751\n\n(cherry picked from commit 89095295036d0dbd180fa4265205f0d666b3c0d9)\n\n* uncomment testcase after testing\n\n(cherry picked from commit 235d329118764005c2ace77bc7b26e472bcd5e14)\n\n* savepoint remove local setting files\n\n(cherry picked from commit f7b4872a347938d090193a55beba3ff2a31bcefa)\n\n* backout chags for a different pr, adjust unit test\n\n(cherry picked from commit 60463b5da7c885ce4e90ff9cf2d81c7682d59b0b)\n\n* changes from code review\n\n(cherry picked from commit 42b0fbd0a665cf409b85e329151f5b5d3e2a07e8)\n\n* Resolve remaining feedback for AVRO-2825 and fix complex logical type parsing\n\n* Fix CodeQL warning: Use pattern matching to assert logicalSchema type safely\n\n* Remove accidentally tracked launchSettings.json\n\n---------\n\nCo-authored-by: Tom Bruns \u003cTBruns@tql.com\u003e"
    },
    {
      "commit": "892d6997dcb65627560b04bd76c5a3dd97666cdf",
      "tree": "98810a003a26bc4a126d3908e781354466a4c2e1",
      "parents": [
        "974961d97a84d3601113d0f3cdc41db6580d1b6b"
      ],
      "author": {
        "name": "Cedric",
        "email": "48430048+cedricholzer@users.noreply.github.com",
        "time": "Thu May 07 20:33:39 2026 +0200"
      },
      "committer": {
        "name": "GitHub",
        "email": "noreply@github.com",
        "time": "Thu May 07 20:33:39 2026 +0200"
      },
      "message": "AVRO-4238: [java] Fix adding union fields with array default value (#3730)\n\nWhen FastReader was enabled and a field of type Union\u003cArray, ...\u003e\nwith an Array as default value was added, an AvroRuntimeException\noccurred during Schema Evolution.\n\nThis change resolves this bug in FastReaderBuilder.java, allowing the\nSchema Migration to succeed as specified."
    },
    {
      "commit": "974961d97a84d3601113d0f3cdc41db6580d1b6b",
      "tree": "7f4df4c129b25984590325db74ad4f7b98f9aee0",
      "parents": [
        "96389ebf4d03ca2ee9c59a1083cde1bcd5b307c0"
      ],
      "author": {
        "name": "Santosh Pingale",
        "email": "3813695+santosh-d3vpl3x@users.noreply.github.com",
        "time": "Thu May 07 19:22:05 2026 +0200"
      },
      "committer": {
        "name": "GitHub",
        "email": "noreply@github.com",
        "time": "Thu May 07 19:22:05 2026 +0200"
      },
      "message": "AVRO-4225: Fix ClassCastException in FastReaderBuilder for java-class attribute (#3715)\n\nWhen using GenericDatumReader with schemas containing java-class\nattributes on string fields, FastReaderBuilder.getTransformingStringReader()\nwas casting stringReader.read() directly to String, but GenericData\nreturns Utf8, causing ClassCastException.\n\nFix by explicitly handling both Utf8 and String types, consistent with\nthe rest of the Avro codebase.\n\nCo-authored-by: Kevin Burke \u003ckburke@twilio.com\u003e"
    },
    {
      "commit": "96389ebf4d03ca2ee9c59a1083cde1bcd5b307c0",
      "tree": "fb3f3577b11428ee9fbd926b77ef56788994fffc",
      "parents": [
        "343a9c749a9320e7bf004ec6458cb27dfc5b61ab"
      ],
      "author": {
        "name": "kunal sevkani",
        "email": "34139921+kunalmnnit@users.noreply.github.com",
        "time": "Thu May 07 22:21:15 2026 +0530"
      },
      "committer": {
        "name": "GitHub",
        "email": "noreply@github.com",
        "time": "Thu May 07 18:51:15 2026 +0200"
      },
      "message": "AVRO-4253: Avoid logging datum values in UnresolvedUnionException message (#3764)\n\nUnresolvedUnionException previously included the string representation\nof the unresolved datum in its exception message. When this exception\npropagates to generic error handlers (e.g. in Kafka Connect runtime),\nthe datum value — which may contain sensitive user data — gets written\nto log files.\n\nReplace the datum\u0027s toString() with its class name in the exception\nmessage. The actual datum object remains accessible via\ngetUnresolvedDatum() for callers that need it for programmatic use."
    },
    {
      "commit": "343a9c749a9320e7bf004ec6458cb27dfc5b61ab",
      "tree": "83250f6e34c46666e33af5f3edd024c97b8ad5de",
      "parents": [
        "8dffb87e5f10c4ddb3353b6d83b2d7fab5e30cd7"
      ],
      "author": {
        "name": "Andrew Pilloud",
        "email": "5972627+apilloud@users.noreply.github.com",
        "time": "Tue May 05 11:16:56 2026 -0700"
      },
      "committer": {
        "name": "GitHub",
        "email": "noreply@github.com",
        "time": "Tue May 05 20:16:56 2026 +0200"
      },
      "message": "Fix misaligned pointer use in BufferDetail.hh and BufferReader.hh (#3740)"
    },
    {
      "commit": "8dffb87e5f10c4ddb3353b6d83b2d7fab5e30cd7",
      "tree": "642ee17181aec711b03ff29f68d8ac6fa133b9de",
      "parents": [
        "f144f45f3ebf8a7cdde30ff0d407b9fb2f048c76"
      ],
      "author": {
        "name": "Ismaël Mejía",
        "email": "iemejia@gmail.com",
        "time": "Tue May 05 19:58:18 2026 +0200"
      },
      "committer": {
        "name": "GitHub",
        "email": "noreply@github.com",
        "time": "Tue May 05 19:58:18 2026 +0200"
      },
      "message": "AVRO-4252: Update JS dependencies with security issues (#3753)"
    },
    {
      "commit": "f144f45f3ebf8a7cdde30ff0d407b9fb2f048c76",
      "tree": "4188555e4d7d6e837cf498f9ddfcc56c6eac194f",
      "parents": [
        "782fb6362c354e65e84a1f2ede48a53b5c219bc9"
      ],
      "author": {
        "name": "dependabot[bot]",
        "email": "49699333+dependabot[bot]@users.noreply.github.com",
        "time": "Tue May 05 19:46:01 2026 +0200"
      },
      "committer": {
        "name": "GitHub",
        "email": "noreply@github.com",
        "time": "Tue May 05 19:46:01 2026 +0200"
      },
      "message": "Bump com.github.luben:zstd-jni from 1.5.7-7 to 1.5.7-8 in /lang/java (#3761)\n\nBumps [com.github.luben:zstd-jni](https://github.com/luben/zstd-jni) from 1.5.7-7 to 1.5.7-8.\n- [Commits](https://github.com/luben/zstd-jni/compare/v1.5.7-7...v1.5.7-8)\n\n---\nupdated-dependencies:\n- dependency-name: com.github.luben:zstd-jni\n  dependency-version: 1.5.7-8\n  dependency-type: direct:production\n  update-type: version-update:semver-patch\n...\n\nSigned-off-by: dependabot[bot] \u003csupport@github.com\u003e\nCo-authored-by: dependabot[bot] \u003c49699333+dependabot[bot]@users.noreply.github.com\u003e"
    },
    {
      "commit": "782fb6362c354e65e84a1f2ede48a53b5c219bc9",
      "tree": "51816db3886138e3663cb038f66cb076f06d6897",
      "parents": [
        "048b1debebcf74e96b787315d11138597dcbd13c"
      ],
      "author": {
        "name": "dependabot[bot]",
        "email": "49699333+dependabot[bot]@users.noreply.github.com",
        "time": "Tue May 05 19:45:27 2026 +0200"
      },
      "committer": {
        "name": "GitHub",
        "email": "noreply@github.com",
        "time": "Tue May 05 19:45:27 2026 +0200"
      },
      "message": "Bump grpc.version from 1.80.0 to 1.81.0 in /lang/java (#3759)\n\nBumps `grpc.version` from 1.80.0 to 1.81.0.\n\nUpdates `io.grpc:grpc-core` from 1.80.0 to 1.81.0\n- [Release notes](https://github.com/grpc/grpc-java/releases)\n- [Commits](https://github.com/grpc/grpc-java/compare/v1.80.0...v1.81.0)\n\nUpdates `io.grpc:grpc-stub` from 1.80.0 to 1.81.0\n- [Release notes](https://github.com/grpc/grpc-java/releases)\n- [Commits](https://github.com/grpc/grpc-java/compare/v1.80.0...v1.81.0)\n\nUpdates `io.grpc:grpc-netty` from 1.80.0 to 1.81.0\n- [Release notes](https://github.com/grpc/grpc-java/releases)\n- [Commits](https://github.com/grpc/grpc-java/compare/v1.80.0...v1.81.0)\n\n---\nupdated-dependencies:\n- dependency-name: io.grpc:grpc-core\n  dependency-version: 1.81.0\n  dependency-type: direct:production\n  update-type: version-update:semver-minor\n- dependency-name: io.grpc:grpc-stub\n  dependency-version: 1.81.0\n  dependency-type: direct:production\n  update-type: version-update:semver-minor\n- dependency-name: io.grpc:grpc-netty\n  dependency-version: 1.81.0\n  dependency-type: direct:development\n  update-type: version-update:semver-minor\n...\n\nSigned-off-by: dependabot[bot] \u003csupport@github.com\u003e\nCo-authored-by: dependabot[bot] \u003c49699333+dependabot[bot]@users.noreply.github.com\u003e"
    },
    {
      "commit": "048b1debebcf74e96b787315d11138597dcbd13c",
      "tree": "92ca18706f4d9d88e801cf61689b954854658fbb",
      "parents": [
        "8cdb621ca33618c1cdeedf86bd75bdee90b898f6"
      ],
      "author": {
        "name": "dependabot[bot]",
        "email": "49699333+dependabot[bot]@users.noreply.github.com",
        "time": "Tue May 05 19:45:10 2026 +0200"
      },
      "committer": {
        "name": "GitHub",
        "email": "noreply@github.com",
        "time": "Tue May 05 19:45:10 2026 +0200"
      },
      "message": "Bump postcss from 8.5.12 to 8.5.13 in /doc (#3758)\n\nBumps [postcss](https://github.com/postcss/postcss) from 8.5.12 to 8.5.13.\n- [Release notes](https://github.com/postcss/postcss/releases)\n- [Changelog](https://github.com/postcss/postcss/blob/main/CHANGELOG.md)\n- [Commits](https://github.com/postcss/postcss/compare/8.5.12...8.5.13)\n\n---\nupdated-dependencies:\n- dependency-name: postcss\n  dependency-version: 8.5.13\n  dependency-type: direct:development\n  update-type: version-update:semver-patch\n...\n\nSigned-off-by: dependabot[bot] \u003csupport@github.com\u003e\nCo-authored-by: dependabot[bot] \u003c49699333+dependabot[bot]@users.noreply.github.com\u003e"
    },
    {
      "commit": "8cdb621ca33618c1cdeedf86bd75bdee90b898f6",
      "tree": "bd26a46c67c7243ed4e8111d56185087dae9f075",
      "parents": [
        "2cd8431ca3ae95849a05b4105f8bcc9fe5d4b4e1"
      ],
      "author": {
        "name": "dependabot[bot]",
        "email": "49699333+dependabot[bot]@users.noreply.github.com",
        "time": "Tue May 05 19:44:56 2026 +0200"
      },
      "committer": {
        "name": "GitHub",
        "email": "noreply@github.com",
        "time": "Tue May 05 19:44:56 2026 +0200"
      },
      "message": "Bump com.fasterxml.jackson:jackson-bom in /lang/java (#3757)\n\nBumps [com.fasterxml.jackson:jackson-bom](https://github.com/FasterXML/jackson-bom) from 2.21.2 to 2.21.3.\n- [Commits](https://github.com/FasterXML/jackson-bom/compare/jackson-bom-2.21.2...jackson-bom-2.21.3)\n\n---\nupdated-dependencies:\n- dependency-name: com.fasterxml.jackson:jackson-bom\n  dependency-version: 2.21.3\n  dependency-type: direct:production\n  update-type: version-update:semver-patch\n...\n\nSigned-off-by: dependabot[bot] \u003csupport@github.com\u003e\nCo-authored-by: dependabot[bot] \u003c49699333+dependabot[bot]@users.noreply.github.com\u003e"
    },
    {
      "commit": "2cd8431ca3ae95849a05b4105f8bcc9fe5d4b4e1",
      "tree": "54848bfcd9afb70a503d1823e9e751c2696c4068",
      "parents": [
        "5af5735cec1ed939ad40f4f599e099fd2d2b29e8"
      ],
      "author": {
        "name": "Valentin Valls",
        "email": "valentin.valls@esrf.fr",
        "time": "Sat May 02 10:08:00 2026 +0200"
      },
      "committer": {
        "name": "GitHub",
        "email": "noreply@github.com",
        "time": "Sat May 02 10:08:00 2026 +0200"
      },
      "message": "Fixed byte compare (#3710)"
    },
    {
      "commit": "5af5735cec1ed939ad40f4f599e099fd2d2b29e8",
      "tree": "94246694de0975a4ffeb31a56a5c87c9d3c86d3b",
      "parents": [
        "64ac2975ec26c59a322d5d110c300741792424f4"
      ],
      "author": {
        "name": "ChristophMajcenAtXxxlutz",
        "email": "Christoph.Majcen@xxxl.digital",
        "time": "Sat May 02 09:50:50 2026 +0200"
      },
      "committer": {
        "name": "GitHub",
        "email": "noreply@github.com",
        "time": "Sat May 02 09:50:50 2026 +0200"
      },
      "message": "AVRO-4162: [csharp] Fix AvroDecimal.CompareTo for values with different scales (#3744)\n\n* fix(AVRO-4162): dotnet AvroDecimal.CompareTo for values with different scale\n\n* fix(AVRO-4162): Make tests not culture-sensitive"
    },
    {
      "commit": "64ac2975ec26c59a322d5d110c300741792424f4",
      "tree": "f9689594d5666f99817a30448ef04e1644321da8",
      "parents": [
        "875c429012cdbf2ab8dadd15940170630b26a2e9"
      ],
      "author": {
        "name": "Ismaël Mejía",
        "email": "iemejia@gmail.com",
        "time": "Fri May 01 08:53:12 2026 +0200"
      },
      "committer": {
        "name": "GitHub",
        "email": "noreply@github.com",
        "time": "Fri May 01 08:53:12 2026 +0200"
      },
      "message": "AVRO-4250: [build] Run github actions test workflows for the maintenance branches (#3748)"
    },
    {
      "commit": "875c429012cdbf2ab8dadd15940170630b26a2e9",
      "tree": "86561af5d8793db0e3d417076f5a56e5ff9364af",
      "parents": [
        "fed00117056cdc3dad424cf8442c2d38775e4658"
      ],
      "author": {
        "name": "Ismaël Mejía",
        "email": "iemejia@gmail.com",
        "time": "Fri May 01 08:47:43 2026 +0200"
      },
      "committer": {
        "name": "GitHub",
        "email": "noreply@github.com",
        "time": "Fri May 01 08:47:43 2026 +0200"
      },
      "message": "AVRO-4241: [Java] BinaryDecoder should verify available bytes before reading (#3725)\n\n* AVRO-4241: [Java] BinaryDecoder should verify available bytes before reading\n\nAdd ensureAvailableBytes() pre-check in readString, readBytes,\nreadArrayStart, arrayNext, readMapStart, and mapNext to verify the\nsource has sufficient data before proceeding.\n\nByte-array-backed sources return an exact remaining count.\nStream-backed sources return buffered bytes plus InputStream.available(),\nwhich is reliable for the finite streams used by DataFileReader and\nDataFileStream.\n\nIncludes regression tests and updated array/map limit tests.\n\n* AVRO-4241: [Java] Simplify no-op validatioin code and fix possible int overflow per PR comments\n\n* AVRO-4241: Test the overhead of {@code minBytesPerElement} computation on GenericDatumReader\n\nBenchmark to measure the overhead of {@code minBytesPerElement} computation during array/map decoding via {@link GenericDatumReader}. Tests complex, wide, and recursive schema structures to verify that the per-block schema traversal cost is acceptable."
    },
    {
      "commit": "fed00117056cdc3dad424cf8442c2d38775e4658",
      "tree": "5df8bedb87d73c7a08f66ec5bb1f75d508dce84f",
      "parents": [
        "c52932696530c43d978f49ff90c061656039fc89"
      ],
      "author": {
        "name": "dependabot[bot]",
        "email": "49699333+dependabot[bot]@users.noreply.github.com",
        "time": "Mon Apr 27 09:23:20 2026 +0300"
      },
      "committer": {
        "name": "GitHub",
        "email": "noreply@github.com",
        "time": "Mon Apr 27 09:23:20 2026 +0300"
      },
      "message": "Bump postcss from 8.5.10 to 8.5.12 in /doc (#3741)\n\nBumps [postcss](https://github.com/postcss/postcss) from 8.5.10 to 8.5.12.\n- [Release notes](https://github.com/postcss/postcss/releases)\n- [Changelog](https://github.com/postcss/postcss/blob/main/CHANGELOG.md)\n- [Commits](https://github.com/postcss/postcss/compare/8.5.10...8.5.12)\n\n---\nupdated-dependencies:\n- dependency-name: postcss\n  dependency-version: 8.5.12\n  dependency-type: direct:development\n  update-type: version-update:semver-patch\n...\n\nSigned-off-by: dependabot[bot] \u003csupport@github.com\u003e\nCo-authored-by: dependabot[bot] \u003c49699333+dependabot[bot]@users.noreply.github.com\u003e"
    },
    {
      "commit": "c52932696530c43d978f49ff90c061656039fc89",
      "tree": "f8fed04af1c2ed0c9f76de2061cb3e83a8c96e2d",
      "parents": [
        "dc037890de66c4af4fd4ad6eb33672931d302cb1"
      ],
      "author": {
        "name": "dependabot[bot]",
        "email": "49699333+dependabot[bot]@users.noreply.github.com",
        "time": "Mon Apr 27 09:23:07 2026 +0300"
      },
      "committer": {
        "name": "GitHub",
        "email": "noreply@github.com",
        "time": "Mon Apr 27 09:23:07 2026 +0300"
      },
      "message": "Bump junit5.version from 5.14.3 to 5.14.4 in /lang/java (#3742)\n\nBumps `junit5.version` from 5.14.3 to 5.14.4.\n\nUpdates `org.junit.vintage:junit-vintage-engine` from 5.14.3 to 5.14.4\n- [Release notes](https://github.com/junit-team/junit-framework/releases)\n- [Commits](https://github.com/junit-team/junit-framework/compare/r5.14.3...r5.14.4)\n\nUpdates `org.junit.jupiter:junit-jupiter` from 5.14.3 to 5.14.4\n- [Release notes](https://github.com/junit-team/junit-framework/releases)\n- [Commits](https://github.com/junit-team/junit-framework/compare/r5.14.3...r5.14.4)\n\n---\nupdated-dependencies:\n- dependency-name: org.junit.vintage:junit-vintage-engine\n  dependency-version: 5.14.4\n  dependency-type: direct:development\n  update-type: version-update:semver-patch\n- dependency-name: org.junit.jupiter:junit-jupiter\n  dependency-version: 5.14.4\n  dependency-type: direct:development\n  update-type: version-update:semver-patch\n...\n\nSigned-off-by: dependabot[bot] \u003csupport@github.com\u003e\nCo-authored-by: dependabot[bot] \u003c49699333+dependabot[bot]@users.noreply.github.com\u003e"
    },
    {
      "commit": "dc037890de66c4af4fd4ad6eb33672931d302cb1",
      "tree": "74c660287dd4eb484030b4abd1220ea99613d195",
      "parents": [
        "79017ee391c04f60bdffd5fecf9ecc27c1b1f420"
      ],
      "author": {
        "name": "dependabot[bot]",
        "email": "49699333+dependabot[bot]@users.noreply.github.com",
        "time": "Mon Apr 27 09:22:52 2026 +0300"
      },
      "committer": {
        "name": "GitHub",
        "email": "noreply@github.com",
        "time": "Mon Apr 27 09:22:52 2026 +0300"
      },
      "message": "Bump System.CodeDom from 10.0.6 to 10.0.7 (#3743)\n\n---\nupdated-dependencies:\n- dependency-name: System.CodeDom\n  dependency-version: 10.0.7\n  dependency-type: direct:production\n  update-type: version-update:semver-patch\n...\n\nSigned-off-by: dependabot[bot] \u003csupport@github.com\u003e\nCo-authored-by: dependabot[bot] \u003c49699333+dependabot[bot]@users.noreply.github.com\u003e"
    },
    {
      "commit": "79017ee391c04f60bdffd5fecf9ecc27c1b1f420",
      "tree": "1477e8b35d214133719d301dec18df76ad612a01",
      "parents": [
        "f7cb68167857e519320893f3e838d0675f0d89e6"
      ],
      "author": {
        "name": "dependabot[bot]",
        "email": "49699333+dependabot[bot]@users.noreply.github.com",
        "time": "Mon Apr 20 08:33:46 2026 +0300"
      },
      "committer": {
        "name": "GitHub",
        "email": "noreply@github.com",
        "time": "Mon Apr 20 08:33:46 2026 +0300"
      },
      "message": "Bump autoprefixer from 10.4.27 to 10.5.0 in /doc (#3735)\n\nBumps [autoprefixer](https://github.com/postcss/autoprefixer) from 10.4.27 to 10.5.0.\n- [Release notes](https://github.com/postcss/autoprefixer/releases)\n- [Changelog](https://github.com/postcss/autoprefixer/blob/main/CHANGELOG.md)\n- [Commits](https://github.com/postcss/autoprefixer/compare/10.4.27...10.5.0)\n\n---\nupdated-dependencies:\n- dependency-name: autoprefixer\n  dependency-version: 10.5.0\n  dependency-type: direct:development\n  update-type: version-update:semver-minor\n...\n\nSigned-off-by: dependabot[bot] \u003csupport@github.com\u003e\nCo-authored-by: dependabot[bot] \u003c49699333+dependabot[bot]@users.noreply.github.com\u003e"
    },
    {
      "commit": "f7cb68167857e519320893f3e838d0675f0d89e6",
      "tree": "eb309d70584a25b6a7f2002c78c8f26f517821a0",
      "parents": [
        "f6b7d337c45134dc5fd6031c28b38ba78d4dd720"
      ],
      "author": {
        "name": "dependabot[bot]",
        "email": "49699333+dependabot[bot]@users.noreply.github.com",
        "time": "Mon Apr 20 08:33:37 2026 +0300"
      },
      "committer": {
        "name": "GitHub",
        "email": "noreply@github.com",
        "time": "Mon Apr 20 08:33:37 2026 +0300"
      },
      "message": "Bump coverlet.collector from 8.0.1 to 10.0.0 (#3737)\n\n---\nupdated-dependencies:\n- dependency-name: coverlet.collector\n  dependency-version: 10.0.0\n  dependency-type: direct:production\n  update-type: version-update:semver-major\n...\n\nSigned-off-by: dependabot[bot] \u003csupport@github.com\u003e\nCo-authored-by: dependabot[bot] \u003c49699333+dependabot[bot]@users.noreply.github.com\u003e\nCo-authored-by: Martin Grigorov \u003cmartin-g@users.noreply.github.com\u003e"
    },
    {
      "commit": "f6b7d337c45134dc5fd6031c28b38ba78d4dd720",
      "tree": "02bbe21d0fb2357ace5a9771a7183d92bb2f756e",
      "parents": [
        "fd37a8f3da6e06dd0db33780b04b4be3fcd97498"
      ],
      "author": {
        "name": "dependabot[bot]",
        "email": "49699333+dependabot[bot]@users.noreply.github.com",
        "time": "Mon Apr 20 08:25:13 2026 +0300"
      },
      "committer": {
        "name": "GitHub",
        "email": "noreply@github.com",
        "time": "Mon Apr 20 08:25:13 2026 +0300"
      },
      "message": "Bump astral-sh/setup-uv from 8.0.0 to 8.1.0 (#3736)\n\nBumps [astral-sh/setup-uv](https://github.com/astral-sh/setup-uv) from 8.0.0 to 8.1.0.\n- [Release notes](https://github.com/astral-sh/setup-uv/releases)\n- [Commits](https://github.com/astral-sh/setup-uv/compare/cec208311dfd045dd5311c1add060b2062131d57...08807647e7069bb48b6ef5acd8ec9567f424441b)\n\n---\nupdated-dependencies:\n- dependency-name: astral-sh/setup-uv\n  dependency-version: 8.1.0\n  dependency-type: direct:production\n  update-type: version-update:semver-minor\n...\n\nSigned-off-by: dependabot[bot] \u003csupport@github.com\u003e\nCo-authored-by: dependabot[bot] \u003c49699333+dependabot[bot]@users.noreply.github.com\u003e"
    },
    {
      "commit": "fd37a8f3da6e06dd0db33780b04b4be3fcd97498",
      "tree": "b89454f5641b4d2d98cf90da2a94441aae814e3c",
      "parents": [
        "405dcafbf9c66398c53d9fbb90bff6cfc9162257"
      ],
      "author": {
        "name": "dependabot[bot]",
        "email": "49699333+dependabot[bot]@users.noreply.github.com",
        "time": "Mon Apr 20 08:24:16 2026 +0300"
      },
      "committer": {
        "name": "GitHub",
        "email": "noreply@github.com",
        "time": "Mon Apr 20 08:24:16 2026 +0300"
      },
      "message": "Bump postcss from 8.5.9 to 8.5.10 in /doc (#3734)\n\nBumps [postcss](https://github.com/postcss/postcss) from 8.5.9 to 8.5.10.\n- [Release notes](https://github.com/postcss/postcss/releases)\n- [Changelog](https://github.com/postcss/postcss/blob/main/CHANGELOG.md)\n- [Commits](https://github.com/postcss/postcss/compare/8.5.9...8.5.10)\n\n---\nupdated-dependencies:\n- dependency-name: postcss\n  dependency-version: 8.5.10\n  dependency-type: direct:development\n  update-type: version-update:semver-patch\n...\n\nSigned-off-by: dependabot[bot] \u003csupport@github.com\u003e\nCo-authored-by: dependabot[bot] \u003c49699333+dependabot[bot]@users.noreply.github.com\u003e"
    },
    {
      "commit": "405dcafbf9c66398c53d9fbb90bff6cfc9162257",
      "tree": "5a6530a8d878ecda0ce3cf765aac93f9db7fb525",
      "parents": [
        "f327e1a94ff6e57ae6055e53f06455416a897646"
      ],
      "author": {
        "name": "dependabot[bot]",
        "email": "49699333+dependabot[bot]@users.noreply.github.com",
        "time": "Mon Apr 20 08:23:03 2026 +0300"
      },
      "committer": {
        "name": "GitHub",
        "email": "noreply@github.com",
        "time": "Mon Apr 20 08:23:03 2026 +0300"
      },
      "message": "Bump coverlet.msbuild from 8.0.1 to 10.0.0 (#3738)\n\n---\nupdated-dependencies:\n- dependency-name: coverlet.msbuild\n  dependency-version: 10.0.0\n  dependency-type: direct:production\n  update-type: version-update:semver-major\n...\n\nSigned-off-by: dependabot[bot] \u003csupport@github.com\u003e\nCo-authored-by: dependabot[bot] \u003c49699333+dependabot[bot]@users.noreply.github.com\u003e"
    },
    {
      "commit": "f327e1a94ff6e57ae6055e53f06455416a897646",
      "tree": "bae053224117090e45a8e63e8884404724527af8",
      "parents": [
        "cb54bb4e8c67ef5e598ccaa99bf96bd520a9b66e"
      ],
      "author": {
        "name": "dependabot[bot]",
        "email": "49699333+dependabot[bot]@users.noreply.github.com",
        "time": "Mon Apr 20 08:22:48 2026 +0300"
      },
      "committer": {
        "name": "GitHub",
        "email": "noreply@github.com",
        "time": "Mon Apr 20 08:22:48 2026 +0300"
      },
      "message": "Bump System.CodeDom from 10.0.5 to 10.0.6 (#3739)\n\n---\nupdated-dependencies:\n- dependency-name: System.CodeDom\n  dependency-version: 10.0.6\n  dependency-type: direct:production\n  update-type: version-update:semver-patch\n...\n\nSigned-off-by: dependabot[bot] \u003csupport@github.com\u003e\nCo-authored-by: dependabot[bot] \u003c49699333+dependabot[bot]@users.noreply.github.com\u003e"
    }
  ],
  "next": "cb54bb4e8c67ef5e598ccaa99bf96bd520a9b66e"
}
