)]}'
{
  "log": [
    {
      "commit": "858bb7868b489368873444ba9bffbd59020c4796",
      "tree": "cc31c960f05754341c1a82d3bd3c3a43a33ada7a",
      "parents": [
        "41641261d12de93f179d48eee40221ecfb1b0fd2"
      ],
      "author": {
        "name": "Elliotte Rusty Harold",
        "email": "elharo@users.noreply.github.com",
        "time": "Wed Jul 29 11:02:09 2026 +0000"
      },
      "committer": {
        "name": "GitHub",
        "email": "noreply@github.com",
        "time": "Wed Jul 29 11:02:09 2026 +0000"
      },
      "message": "Fix documentation issues across site docs (#2010)\n\n* Fix documentation issues across site docs\n\n* Fix grammar and clarity in about-checksums.md\n\nCorrected grammatical errors and improved clarity in the explanation of checksum algorithms and their usage.\n\n* Fix grammar and clarity in API compatibility documentation\n\n* Apply suggestion from @gnodet\n\nCo-authored-by: Guillaume Nodet \u003cgnodet@gmail.com\u003e\n\n* Fix wording and clarity in common misconceptions section\n\nCorrected phrasing and improved clarity in the text.\n\n* Fix grammar and clarity in misconceptions document\n\nCorrected grammatical errors and improved clarity in the explanation of test and runtime graphs in Maven.\n\n* Fix compile error in code example and indentation inconsistency\n\n* Potential fix for pull request finding\n\nCo-authored-by: Copilot Autofix powered by AI \u003c175728472+Copilot@users.noreply.github.com\u003e\n\n* Improve clarity on Resolver\u0027s completeness and dependencies\n\nClarified the explanation of Resolver\u0027s completeness and its dependency on the maven-resolver-provider module.\n\n* Refine about-checksums.md for clarity and accuracy\n\nUpdated language for clarity and precision regarding checksums and their security implications.\n\n* Improve instructions for handling broken MRMs\n\nClarified user instructions on disabling prefix discovery for broken Maven Repository Managers.\n\n* Update src/site/markdown/about-checksums.md\n\nCo-authored-by: Guillaume Nodet \u003cgnodet@gmail.com\u003e\n\n* Update src/site/markdown/about-checksums.md\n\nCo-authored-by: Guillaume Nodet \u003cgnodet@gmail.com\u003e\n\n* Address review: use SessionBuilder API, fix double space\n\n---------\n\nCo-authored-by: opencode \u003copencode@example.com\u003e\nCo-authored-by: Guillaume Nodet \u003cgnodet@gmail.com\u003e\nCo-authored-by: Copilot Autofix powered by AI \u003c175728472+Copilot@users.noreply.github.com\u003e"
    },
    {
      "commit": "41641261d12de93f179d48eee40221ecfb1b0fd2",
      "tree": "3d4f1e1aea727500f10046cb6d6d2fd824933f54",
      "parents": [
        "757dfc6b6c1b7bd960cb80621a4abad7949a16b2"
      ],
      "author": {
        "name": "dependabot[bot]",
        "email": "49699333+dependabot[bot]@users.noreply.github.com",
        "time": "Tue Jul 28 22:07:27 2026 +0200"
      },
      "committer": {
        "name": "GitHub",
        "email": "noreply@github.com",
        "time": "Tue Jul 28 22:07:27 2026 +0200"
      },
      "message": "Bump sisuVersion from 1.0.1 to 1.1.0 (#2016)\n\nBumps `sisuVersion` from 1.0.1 to 1.1.0.\n\nUpdates `org.eclipse.sisu:org.eclipse.sisu.inject` from 1.0.1 to 1.1.0\n- [Release notes](https://github.com/eclipse-sisu/sisu-project/releases)\n- [Changelog](https://github.com/eclipse-sisu/sisu-project/blob/main/RELEASE.md)\n- [Commits](https://github.com/eclipse-sisu/sisu-project/compare/releases/1.0.1...releases/1.1.0)\n\nUpdates `org.eclipse.sisu:org.eclipse.sisu.plexus` from 1.0.1 to 1.1.0\n- [Release notes](https://github.com/eclipse-sisu/sisu-project/releases)\n- [Changelog](https://github.com/eclipse-sisu/sisu-project/blob/main/RELEASE.md)\n- [Commits](https://github.com/eclipse-sisu/sisu-project/compare/releases/1.0.1...releases/1.1.0)\n\n---\nupdated-dependencies:\n- dependency-name: org.eclipse.sisu:org.eclipse.sisu.inject\n  dependency-version: 1.1.0\n  dependency-type: direct:production\n  update-type: version-update:semver-minor\n- dependency-name: org.eclipse.sisu:org.eclipse.sisu.plexus\n  dependency-version: 1.1.0\n  dependency-type: direct:production\n  update-type: version-update:semver-minor\n...\n\nSigned-off-by: dependabot[bot] \u003csupport@github.com\u003e\nCo-authored-by: dependabot[bot] \u003c49699333+dependabot[bot]@users.noreply.github.com\u003e"
    },
    {
      "commit": "757dfc6b6c1b7bd960cb80621a4abad7949a16b2",
      "tree": "b3780726b41d54b18622b2dfbc7d8076c1afc0d7",
      "parents": [
        "539fc8e3e8eb89bf243ad6fa30bc098748978357"
      ],
      "author": {
        "name": "Konrad Windszus",
        "email": "kwin@apache.org",
        "time": "Mon Jul 27 13:31:28 2026 +0200"
      },
      "committer": {
        "name": "GitHub",
        "email": "noreply@github.com",
        "time": "Mon Jul 27 13:31:28 2026 +0200"
      },
      "message": "Improve rendering of javadoc content (#1981)\n\nRender all inline tags in the same way as the standard doclet.\nSome code simplifications."
    },
    {
      "commit": "539fc8e3e8eb89bf243ad6fa30bc098748978357",
      "tree": "49f55ba9767ff6f06a32075c7b8ebef0e5c16251",
      "parents": [
        "b749cad4ce66d779d6729018bfe55bec06f3d34f"
      ],
      "author": {
        "name": "Elliotte Rusty Harold",
        "email": "elharo@users.noreply.github.com",
        "time": "Fri Jul 24 12:03:51 2026 +0000"
      },
      "committer": {
        "name": "GitHub",
        "email": "noreply@github.com",
        "time": "Fri Jul 24 14:03:51 2026 +0200"
      },
      "message": "Replace printStackTrace with proper error handling (#2011)\n\nFixes #1999\n\nChanges:\n- **DefaultArtifactResolverTest**: Replace `e.printStackTrace()` with `throw new RuntimeException(e)` so tests properly fail on IO errors instead of silently printing\n- **DefaultSessionDataTest**: Remove redundant `t.printStackTrace()` — error already captured in AtomicReference and asserted\n- **DefaultRepositoryCacheTest**: Same as DefaultSessionDataTest\n- **DependencyCollectorDelegate**: Use local counter fields instead of `result.getExceptions().size()` / `result.getCycles().size()` for thread safety during concurrent collection\n\n---------\n\nCo-authored-by: opencode \u003copencode@example.com\u003e"
    },
    {
      "commit": "b749cad4ce66d779d6729018bfe55bec06f3d34f",
      "tree": "029f65467ee3f2d931cc1ddca073345ddbec62f2",
      "parents": [
        "f164aa904ade545c015bbb2d880ebac0625a04b0"
      ],
      "author": {
        "name": "Elliotte Rusty Harold",
        "email": "elharo@users.noreply.github.com",
        "time": "Fri Jul 24 12:03:16 2026 +0000"
      },
      "committer": {
        "name": "GitHub",
        "email": "noreply@github.com",
        "time": "Fri Jul 24 14:03:16 2026 +0200"
      },
      "message": "Fix InterruptedException silently dropping task in SmartExecutor.Limited.submit(Runnable) (#2012)\n\nFixes #1993\n\nIn `Limited.submit(Runnable)` (line 155), if `semaphore.acquire()` throws `InterruptedException`, the interrupt flag was restored but the caller\u0027s task was never executed — it was silently dropped. The `submit(Callable)` variant correctly handles this by returning a failed `CompletableFuture`.\n\nThis fix throws a `RuntimeException` wrapping the `InterruptedException` after restoring the interrupt flag, so the caller is notified that the task could not be submitted.\n\n---------\n\nCo-authored-by: opencode \u003copencode@example.com\u003e"
    },
    {
      "commit": "f164aa904ade545c015bbb2d880ebac0625a04b0",
      "tree": "d8261361b5b5ce0dc3b7fa7e64320fd2a949c60c",
      "parents": [
        "f11b63bf610d344e1233160960ad9f32bd33765e"
      ],
      "author": {
        "name": "Tamas Cservenak",
        "email": "tamas@cservenak.net",
        "time": "Fri Jul 24 14:01:58 2026 +0200"
      },
      "committer": {
        "name": "GitHub",
        "email": "noreply@github.com",
        "time": "Fri Jul 24 14:01:58 2026 +0200"
      },
      "message": "Enh: Allow validator factory to abstain (#2008)\n\nChanges:\n* allow `ValidatorFactory` to \"abstain\" and return `NOOP`\n* introduce alt execution path for managed dependencies (use cases varies)\n* cache validators per session\n\nFixes: #2007"
    },
    {
      "commit": "f11b63bf610d344e1233160960ad9f32bd33765e",
      "tree": "65479697933872f932025b6a04c9a18da3240732",
      "parents": [
        "651e7b1d1f43035e94001fddf6afb09d5a060705"
      ],
      "author": {
        "name": "Elliotte Rusty Harold",
        "email": "elharo@users.noreply.github.com",
        "time": "Thu Jul 23 13:18:57 2026 +0000"
      },
      "committer": {
        "name": "GitHub",
        "email": "noreply@github.com",
        "time": "Thu Jul 23 13:18:57 2026 +0000"
      },
      "message": "Edit version comparison (#1714)\n\n* Edit version comparison\n\n* undefined\n\n* Fix HTML formatting in package-info.java comments\n\n* Fix typo in package-info.java documentation"
    },
    {
      "commit": "651e7b1d1f43035e94001fddf6afb09d5a060705",
      "tree": "778fe3f369d16faf86fa2b8687c4f8257a7b1134",
      "parents": [
        "838477a48a6cbcc26a51c56fff7f964440f2aaa3"
      ],
      "author": {
        "name": "Tamas Cservenak",
        "email": "tamas@cservenak.net",
        "time": "Mon Jul 20 15:03:11 2026 +0200"
      },
      "committer": {
        "name": "Tamas Cservenak",
        "email": "tamas@cservenak.net",
        "time": "Mon Jul 20 15:03:11 2026 +0200"
      },
      "message": "[maven-release-plugin] prepare for next development iteration\n"
    },
    {
      "commit": "838477a48a6cbcc26a51c56fff7f964440f2aaa3",
      "tree": "b838d9326f1776871f30aa34cb316533f874df6f",
      "parents": [
        "f59888098759883ce95d673b883e29fd09b07a9b"
      ],
      "author": {
        "name": "Tamas Cservenak",
        "email": "tamas@cservenak.net",
        "time": "Mon Jul 20 15:02:53 2026 +0200"
      },
      "committer": {
        "name": "Tamas Cservenak",
        "email": "tamas@cservenak.net",
        "time": "Mon Jul 20 15:02:53 2026 +0200"
      },
      "message": "[maven-release-plugin] prepare release maven-resolver-2.0.21\n"
    },
    {
      "commit": "f59888098759883ce95d673b883e29fd09b07a9b",
      "tree": "b8a5be2ec1b7bdf366a83fc005cb1d4876e40ef6",
      "parents": [
        "1e5d22aeeadebe2942fb011f2c47ba84d5eced12"
      ],
      "author": {
        "name": "Tamas Cservenak",
        "email": "tamas@cservenak.net",
        "time": "Mon Jul 20 14:32:27 2026 +0200"
      },
      "committer": {
        "name": "GitHub",
        "email": "noreply@github.com",
        "time": "Mon Jul 20 14:32:27 2026 +0200"
      },
      "message": "Add ATR meta (#1982)\n\nAdd ATR meta"
    },
    {
      "commit": "1e5d22aeeadebe2942fb011f2c47ba84d5eced12",
      "tree": "c930d70404909786c7ecda02c511adb5b2b8fab5",
      "parents": [
        "f4d1fa9cb1f036b9128d9617e80e4e6cf0098cc2"
      ],
      "author": {
        "name": "Guillaume Nodet",
        "email": "gnodet@gmail.com",
        "time": "Mon Jul 20 08:16:38 2026 +0200"
      },
      "committer": {
        "name": "GitHub",
        "email": "noreply@github.com",
        "time": "Mon Jul 20 08:16:38 2026 +0200"
      },
      "message": "Fix: preserve original trace data when stamping re-entrancy marker (#1980)\n\n* Fix: preserve original trace data when stamping re-entrancy marker\n\nThe re-entrancy detection added in e29d0cda stamps a marker object\ninto the RequestTrace chain. However, it placed the marker as the\ntrace tip data, replacing whatever was there before (typically an\nArtifact set by Maven core). Plugins that walk the trace chain and\ncast getData() to Artifact (e.g. pgpverify-maven-plugin) get a\nClassCastException when they hit the marker object.\n\nThis fix inserts the marker one level deeper in the trace chain and\nre-attaches the original tip data on top, so existing code that\nreads getData() continues to find the expected object. The\nisReentrant() method is unaffected because it walks the full chain\nand will still find the marker.\n\nCo-Authored-By: Claude Opus 4.6 \u003cnoreply@anthropic.com\u003e\n\n* Address review: assert re-entrancy marker identity in parent trace\n\nCo-Authored-By: Claude Opus 4.6 \u003cnoreply@anthropic.com\u003e\n\n---------\n\nCo-authored-by: Claude Opus 4.6 \u003cnoreply@anthropic.com\u003e"
    },
    {
      "commit": "f4d1fa9cb1f036b9128d9617e80e4e6cf0098cc2",
      "tree": "577e0b158c07bef228c835fc25a70abc8eb06a53",
      "parents": [
        "853288956a17c87538cd2ff11e60bea1ce82e318"
      ],
      "author": {
        "name": "Gerd Aschemann",
        "email": "github@aschemann.net",
        "time": "Sat Jul 18 15:36:27 2026 +0200"
      },
      "committer": {
        "name": "GitHub",
        "email": "noreply@github.com",
        "time": "Sat Jul 18 15:36:27 2026 +0200"
      },
      "message": "RRF: self-heal from provably broken auto-discovered prefixes files (#1976)\n\nVerify the first denied path per repository against the repository\nitself (one peek, bounded); if it exists, the auto-discovered prefixes\nfile is provably wrong: warn and ignore it for the session. User-provided\nfiles stay authoritative. Opt-out:\n-Daether.remoteRepositoryFilter.prefixes.verifyDenied\u003dfalse\n\nReal-world instance: repo.jenkins-ci.org/public serving a leaked\nmember-repo prefixes file, breaking every Jenkins-ecosystem build on\nMaven 4 and 3.10 defaults (jenkins-infra/helpdesk#5231).\n\nRefs apache/maven#11856\n\nCo-Authored-By: Claude Fable 5 \u003cnoreply@anthropic.com\u003e"
    },
    {
      "commit": "853288956a17c87538cd2ff11e60bea1ce82e318",
      "tree": "f01c9eb07e6340b8f5c982e2148561449a02bd07",
      "parents": [
        "0feb2143e382e9095928f14c465a04f52ed99fd8"
      ],
      "author": {
        "name": "Tamas Cservenak",
        "email": "tamas@cservenak.net",
        "time": "Sat Jul 18 14:10:38 2026 +0200"
      },
      "committer": {
        "name": "GitHub",
        "email": "noreply@github.com",
        "time": "Sat Jul 18 14:10:38 2026 +0200"
      },
      "message": "Bug: in certain cases Resolver caused build failure (#1975)\n\nWhile it should not. The result repository MAY be `null` in certain cases, and that resulted in omission of recording ArtifactNotFoundEx as addException method filters out null repositories and/or exceptions.\n\nWhile not biggie, later on, if this resolution was in fact happening for a POM, despite descriptor policy would be \"ignore missing\" (default in Maven 3 and 4), due not recorded ANFex, this error would not be recognized as \"missing POM\", and would fail the build or artifact collection or anything involving reading descriptor."
    },
    {
      "commit": "0feb2143e382e9095928f14c465a04f52ed99fd8",
      "tree": "e1302dc5f811e85a21a05ae9971b732e158148c1",
      "parents": [
        "f97423550e975bd555833926b6fec60712463e56"
      ],
      "author": {
        "name": "Tamas Cservenak",
        "email": "tamas@cservenak.net",
        "time": "Sat Jul 18 12:44:54 2026 +0200"
      },
      "committer": {
        "name": "GitHub",
        "email": "noreply@github.com",
        "time": "Sat Jul 18 12:44:54 2026 +0200"
      },
      "message": "Feat: config to close connection at end of tx (#1978)\n\nNew config option to make URL transport close connection at end of each transaction."
    },
    {
      "commit": "f97423550e975bd555833926b6fec60712463e56",
      "tree": "d4b15c3d5900300056675262b60d2673b47d3b70",
      "parents": [
        "dbaf30986168a4c66700193fba7b80b651a84445"
      ],
      "author": {
        "name": "Konrad Windszus",
        "email": "kwin@apache.org",
        "time": "Sat Jul 18 11:43:18 2026 +0200"
      },
      "committer": {
        "name": "Konrad Windszus",
        "email": "konrad@windszus.net",
        "time": "Sat Jul 18 12:26:46 2026 +0200"
      },
      "message": "Do not check UrlTransporter for open connections after close\n\nConnection pooling for HttpUrlTransporter is managed by JRE with\nno way to explicitly close idle connections\n(compare with\nhttps://docs.oracle.com/javase/6/docs/technotes/guides/net/http-keepalive.html)"
    },
    {
      "commit": "dbaf30986168a4c66700193fba7b80b651a84445",
      "tree": "7bc745792a6db38b1766ac7f1e139ceaa2836c0d",
      "parents": [
        "45482a82ce0377d0c7a0d8fc343eeff6b94012ad"
      ],
      "author": {
        "name": "Konrad Windszus",
        "email": "kwin@apache.org",
        "time": "Fri Jul 17 18:22:49 2026 +0200"
      },
      "committer": {
        "name": "GitHub",
        "email": "noreply@github.com",
        "time": "Fri Jul 17 18:22:49 2026 +0200"
      },
      "message": "Make sure to always close input streams bound to responses (#1970)\n\nEnsure all connections are closed when transporter is closed.\nAdd PUT IT where response contains body.\n\nThis closes #1964"
    },
    {
      "commit": "45482a82ce0377d0c7a0d8fc343eeff6b94012ad",
      "tree": "20085e2853559ec8cc45740f9e916bfcb84865c3",
      "parents": [
        "4bb69adc2e1a4d38db665c0e8e87ca70e8372f7c"
      ],
      "author": {
        "name": "Tamas Cservenak",
        "email": "tamas@cservenak.net",
        "time": "Fri Jul 17 14:19:08 2026 +0200"
      },
      "committer": {
        "name": "GitHub",
        "email": "noreply@github.com",
        "time": "Fri Jul 17 14:19:08 2026 +0200"
      },
      "message": "Fix: be more defensive regarding request traces (#1973)\n\nAs they NPE in UTs but would also NPE in calls made by some\nnon-maven callers that usually do not set trace at all."
    },
    {
      "commit": "4bb69adc2e1a4d38db665c0e8e87ca70e8372f7c",
      "tree": "e01952af69a8ca23a779a8e2621968122eb6f09e",
      "parents": [
        "46da42c5f285f9561395b9bf38e077e95b9a9766"
      ],
      "author": {
        "name": "Tamas Cservenak",
        "email": "tamas@cservenak.net",
        "time": "Thu Jul 16 21:41:09 2026 +0200"
      },
      "committer": {
        "name": "Tamas Cservenak",
        "email": "tamas@cservenak.net",
        "time": "Thu Jul 16 21:41:09 2026 +0200"
      },
      "message": "Fix tools classpath\n\nAs it is about to generate new URL transport doco, it has to have\nit in classpath.\n"
    },
    {
      "commit": "46da42c5f285f9561395b9bf38e077e95b9a9766",
      "tree": "324c54c4307037f1d5d1dc232bf665a07e3f5b3e",
      "parents": [
        "80971cc55f7ee8dcede23bf67b97b050121fe16c"
      ],
      "author": {
        "name": "Konrad Windszus",
        "email": "kwin@apache.org",
        "time": "Thu Jul 16 21:24:16 2026 +0200"
      },
      "committer": {
        "name": "GitHub",
        "email": "noreply@github.com",
        "time": "Thu Jul 16 21:24:16 2026 +0200"
      },
      "message": "Use custom doclet to extract configuration metadata with the help of javadoc (#1965)\n\nAllow usage of enum values as types and for default values within configuration "
    },
    {
      "commit": "80971cc55f7ee8dcede23bf67b97b050121fe16c",
      "tree": "5965aa8874d1622eafab80e970aa6fcf91f53f65",
      "parents": [
        "e3dc7915f8cbf1601e8964a29c375b6b637568c7"
      ],
      "author": {
        "name": "Tamas Cservenak",
        "email": "tamas@cservenak.net",
        "time": "Thu Jul 16 19:54:10 2026 +0200"
      },
      "committer": {
        "name": "GitHub",
        "email": "noreply@github.com",
        "time": "Thu Jul 16 19:54:10 2026 +0200"
      },
      "message": "Bump Jetty to 12.1.11 (#1969)\n\nRelease notes:\nhttps://github.com/jetty/jetty.project/releases/tag/jetty-12.1.11"
    },
    {
      "commit": "e3dc7915f8cbf1601e8964a29c375b6b637568c7",
      "tree": "c87f1178a32e835669db306db00e994beca63006",
      "parents": [
        "8c30c4c1e15ceed9cf38a750d077aa6eca8116d6"
      ],
      "author": {
        "name": "Tamas Cservenak",
        "email": "tamas@cservenak.net",
        "time": "Thu Jul 16 19:18:03 2026 +0200"
      },
      "committer": {
        "name": "GitHub",
        "email": "noreply@github.com",
        "time": "Thu Jul 16 19:18:03 2026 +0200"
      },
      "message": "fix: Some since javadoc tags were off; fixed (#1968)\n\nFix Javadoc since tags."
    },
    {
      "commit": "8c30c4c1e15ceed9cf38a750d077aa6eca8116d6",
      "tree": "c87d04870a21a76abfd013c8c65c32369be327dc",
      "parents": [
        "21ab3aec5a75a65fcfed9ee9b388b8d5ae58db69"
      ],
      "author": {
        "name": "Aayush Tiwari",
        "email": "aayushtiwari1001@gmail.com",
        "time": "Thu Jul 16 22:37:10 2026 +0530"
      },
      "committer": {
        "name": "GitHub",
        "email": "noreply@github.com",
        "time": "Thu Jul 16 19:07:10 2026 +0200"
      },
      "message": "Use try-with-resources in AbstractTransporter (#1947)\n\n## Summary\n\n- Refactor `AbstractTransporter` stream handling to use try-with-resources for the close-on-completion paths.\n- Preserve the existing `close\u003dfalse` behavior by leaving download input streams open and flushing upload output streams.\n- Add focused tests for the `utilGet` and `utilPut` close/flush contracts.\n\nCloses apache/maven-resolver#1521.\n\nGenerated-by: Codex"
    },
    {
      "commit": "21ab3aec5a75a65fcfed9ee9b388b8d5ae58db69",
      "tree": "880518b938791173cd920d7c68f1a972150d9e32",
      "parents": [
        "654935fd390dcb0f40e08ed4ede9c2614f2af18e"
      ],
      "author": {
        "name": "Tamas Cservenak",
        "email": "tamas@cservenak.net",
        "time": "Thu Jul 16 18:56:38 2026 +0200"
      },
      "committer": {
        "name": "GitHub",
        "email": "noreply@github.com",
        "time": "Thu Jul 16 18:56:38 2026 +0200"
      },
      "message": "Feat: new (limited) transport (#1966)\n\nMany applications (outside of Maven) integrate Resolver and their use case is almost always \"consume\" (use Resolver to resolve artifacts). Also, many of those applications are still Java 8 level, hence, the JDK transport for them is no-go. On the other hand, there is no lightweight replacement for them, except to use some \"heavyweight\" transporter, but in case of CLI applications this is usually undesirable, as they count every byte.\n\nTransitive hull sizes of several existing transports:\n* jdk - 1.5MB / Java 11+\n* wagon - 1.9MB (without any provider; unusable like this) / Java 8+\n* apache - 2.4MB / Java 8+\n* jetty - 10.9MB / Java 11+\n* minio - 23.5MB / Java 8+\n\nThe new transport has no dependencies and small size:\n* url - 870 KB\n\nThis new transport, while is in Resolver, falls totally outside of \"Maven world\", as nor Maven nor any other Maven-related thing will use it."
    },
    {
      "commit": "654935fd390dcb0f40e08ed4ede9c2614f2af18e",
      "tree": "6ae1c244deef81834f06ad86289a2ab5db20ad6f",
      "parents": [
        "f7c14faad03149edf7b5bd73d16ff1561f60dfcc"
      ],
      "author": {
        "name": "Konrad Windszus",
        "email": "kwin@apache.org",
        "time": "Thu Jul 16 17:51:41 2026 +0200"
      },
      "committer": {
        "name": "Konrad Windszus",
        "email": "konrad@windszus.net",
        "time": "Thu Jul 16 17:57:27 2026 +0200"
      },
      "message": "Fix reporting of HTTP/3 in JdkTransporter\n\nUse enum name, as HttpVersion.HTTP_3 was only added in Java26+"
    },
    {
      "commit": "f7c14faad03149edf7b5bd73d16ff1561f60dfcc",
      "tree": "a9c1ebaf37939830a722003fc6a5216440d88af2",
      "parents": [
        "a0df5d58a1aaaf6ca8f87fa2638fd1fae4b0df7d"
      ],
      "author": {
        "name": "Konrad Windszus",
        "email": "kwin@apache.org",
        "time": "Thu Jul 16 17:34:42 2026 +0200"
      },
      "committer": {
        "name": "GitHub",
        "email": "noreply@github.com",
        "time": "Thu Jul 16 17:34:42 2026 +0200"
      },
      "message": "Expose additional transport details to TransportListener (#1762)\n\nFor HTTP transporters this is:\n- HTTP Version\n- SSL Protocol (only HTTPS)\n- SSL Cipher Suite (only HTTPS)\n- Compression Algorithm (if used and supported by HTTP Client impl)\n\nThis closes #1761\n\n* Use dedicated method in TransportListener for transport properties\n\nExpose transport properties for all tasks (Get, Peek, Put).\nReliably capture SSL context from ApacheTransporter with a dedicated\nrequest executor.\n\n* Fix PR review issues in HttpTransportPropertiesBuilder\n\nRemove unused key \"NUM_BYTES_TRANSFERRED\""
    },
    {
      "commit": "a0df5d58a1aaaf6ca8f87fa2638fd1fae4b0df7d",
      "tree": "cf8f812f8516c7de879ae0e050d103f41e70f841",
      "parents": [
        "79d102b66235f33ad1e6134e18451ac3ee91b44a"
      ],
      "author": {
        "name": "Konrad Windszus",
        "email": "kwin@apache.org",
        "time": "Thu Jul 16 17:30:22 2026 +0200"
      },
      "committer": {
        "name": "GitHub",
        "email": "noreply@github.com",
        "time": "Thu Jul 16 17:30:22 2026 +0200"
      },
      "message": "Support HTTP/3 in Jetty and JRE HTTP Client (#1949)\n\nConsolidate http version configuration among HTTP transporters\nDefault to HTTP/2 in all transporters except Apache HTTP Client 4.x\nBuild additionally with Java 26 in GHA\nIT: Clean up and regenerate key stores\n\nThis closes #1760"
    },
    {
      "commit": "79d102b66235f33ad1e6134e18451ac3ee91b44a",
      "tree": "40f51d9304651fddb33c3182356dd997daece766",
      "parents": [
        "440b14f5c29bdeb1f3bb80d9ffbc0446c76e98de"
      ],
      "author": {
        "name": "dependabot[bot]",
        "email": "49699333+dependabot[bot]@users.noreply.github.com",
        "time": "Tue Jul 14 22:05:02 2026 +0200"
      },
      "committer": {
        "name": "GitHub",
        "email": "noreply@github.com",
        "time": "Tue Jul 14 22:05:02 2026 +0200"
      },
      "message": "Bump apache/maven-gh-actions-shared/.github/workflows/release-drafter.yml (#1963)\n\nBumps [apache/maven-gh-actions-shared/.github/workflows/release-drafter.yml](https://github.com/apache/maven-gh-actions-shared) from 4 to 5.\n- [Commits](https://github.com/apache/maven-gh-actions-shared/compare/v4...v5)\n\n---\nupdated-dependencies:\n- dependency-name: apache/maven-gh-actions-shared/.github/workflows/release-drafter.yml\n  dependency-version: \u00275\u0027\n  dependency-type: direct:production\n  update-type: version-update:semver-major\n...\n\nSigned-off-by: dependabot[bot] \u003csupport@github.com\u003e\nCo-authored-by: dependabot[bot] \u003c49699333+dependabot[bot]@users.noreply.github.com\u003e"
    },
    {
      "commit": "440b14f5c29bdeb1f3bb80d9ffbc0446c76e98de",
      "tree": "99c2747c8e93dab3ffd288c9253d9fbd8df26a17",
      "parents": [
        "e29d0cda88e81e3d96975b51d5fd16829f44a658"
      ],
      "author": {
        "name": "dependabot[bot]",
        "email": "49699333+dependabot[bot]@users.noreply.github.com",
        "time": "Tue Jul 14 22:04:59 2026 +0200"
      },
      "committer": {
        "name": "GitHub",
        "email": "noreply@github.com",
        "time": "Tue Jul 14 22:04:59 2026 +0200"
      },
      "message": "Bump apache/maven-gh-actions-shared/.github/workflows/maven-verify.yml (#1961)\n\nBumps [apache/maven-gh-actions-shared/.github/workflows/maven-verify.yml](https://github.com/apache/maven-gh-actions-shared) from 4 to 5.\n- [Commits](https://github.com/apache/maven-gh-actions-shared/compare/v4...v5)\n\n---\nupdated-dependencies:\n- dependency-name: apache/maven-gh-actions-shared/.github/workflows/maven-verify.yml\n  dependency-version: \u00275\u0027\n  dependency-type: direct:production\n  update-type: version-update:semver-major\n...\n\nSigned-off-by: dependabot[bot] \u003csupport@github.com\u003e\nCo-authored-by: dependabot[bot] \u003c49699333+dependabot[bot]@users.noreply.github.com\u003e"
    },
    {
      "commit": "e29d0cda88e81e3d96975b51d5fd16829f44a658",
      "tree": "9c4d6800c9c6b73242eceacb7b3083098d13c907",
      "parents": [
        "ffcf153754a8149e2a61eefaa3d36000cfe5707e"
      ],
      "author": {
        "name": "Guillaume Nodet",
        "email": "gnodet@gmail.com",
        "time": "Tue Jul 14 22:04:12 2026 +0200"
      },
      "committer": {
        "name": "GitHub",
        "email": "noreply@github.com",
        "time": "Tue Jul 14 22:04:12 2026 +0200"
      },
      "message": "Skip validation and decoration on re-entrant RepositorySystem calls (#1957)\n\n## Summary\n\nMaven 4\u0027s `ArtifactDescriptorReader` → `ModelBuilder` → `ModelResolver` chain re-enters `RepositorySystem` during `collectDependencies`. This breaks the resolver\u0027s single-crossing contract:\n\n- **Validation rejects intermediate state**: `MavenValidator` (registered via the `ValidatorFactory` SPI) rejects uninterpolated `${...}` expressions that are valid intermediate state in transitive POMs during model building\n- **Artifact decorators run redundantly**: decorators applied on inner calls corrupt the resolution result\n- **Reported as**: [MAVEN #12474](https://github.com/apache/maven/issues/12474) — `Invalid Collect Request: null`\n\n### How it works\n\nOn the **outermost** call to any `RepositorySystem` public method, a sentinel marker is stamped into the request\u0027s `RequestTrace`. On **re-entry** (whether on the same thread or a pool thread), `isReentrant()` walks the trace ancestry — if the marker is found, validation and decoration are skipped.\n\nThis leverages the existing `RequestTrace` infrastructure which is already propagated across threads by callers (Maven\u0027s model builder explicitly copies traces to pool threads via `session.setCurrentTrace(trace)`), requiring **no ThreadLocal or session-scoped state**.\n\n### Changes\n\n- `DefaultRepositorySystem`: all public resolution methods check `isReentrant(trace)` before validating/decorating\n- `readArtifactDescriptor`: additionally skips artifact decoration on re-entry\n- Methods without trace-bearing requests (`install`, `deploy`, `newResolutionRepositories`, `newDeploymentRepository`, `flattenDependencyNodes`) always validate — they are terminal operations that don\u0027t participate in re-entrancy\n- New test class `DefaultRepositorySystemReentrancyTest` with 5 tests covering:\n  - Outermost calls run validation\n  - Re-entrant calls skip validation\n  - Re-entrant calls allow uninterpolated expressions (the bug scenario)\n  - Re-entrant `readArtifactDescriptor` skips decoration\n  - Independent calls each validate independently\n\n## Test plan\n\n- [x] All 445 existing tests pass in `maven-resolver-impl`\n- [x] 5 new re-entrancy tests pass\n- [ ] CI build passes\n- [ ] Integration test with Maven 4 against the reproducer from #12474\n\n🤖 Generated with [Claude Code](https://claude.com/claude-code)"
    },
    {
      "commit": "ffcf153754a8149e2a61eefaa3d36000cfe5707e",
      "tree": "7103d9d1c3a93593c43641148892c2863a04ea38",
      "parents": [
        "3d807d4db773c4c02ac1014fddc8fc5444b71a3d"
      ],
      "author": {
        "name": "Tamas Cservenak",
        "email": "tamas@cservenak.net",
        "time": "Tue Jul 14 22:03:34 2026 +0200"
      },
      "committer": {
        "name": "GitHub",
        "email": "noreply@github.com",
        "time": "Tue Jul 14 22:03:34 2026 +0200"
      },
      "message": "Validate path components (#1959)\n\nBut make it reusable as well. When 2.0.21 released, Maven codebase of `DefaultVersionResolver` and `DefaultVersionRangeResolver` should be updated too, and use this util method.\n\nSupersedes (and based on) #1958"
    },
    {
      "commit": "3d807d4db773c4c02ac1014fddc8fc5444b71a3d",
      "tree": "079889adbe0e147bd358d49a6175e3afd41d455f",
      "parents": [
        "fe591022281b81060899008a6b2b47c5c2c1479f"
      ],
      "author": {
        "name": "dependabot[bot]",
        "email": "49699333+dependabot[bot]@users.noreply.github.com",
        "time": "Tue Jul 14 20:54:03 2026 +0200"
      },
      "committer": {
        "name": "GitHub",
        "email": "noreply@github.com",
        "time": "Tue Jul 14 20:54:03 2026 +0200"
      },
      "message": "Bump apache/maven-gh-actions-shared/.github/workflows/stale.yml (#1960)\n\nBumps [apache/maven-gh-actions-shared/.github/workflows/stale.yml](https://github.com/apache/maven-gh-actions-shared) from 4 to 5.\n- [Commits](https://github.com/apache/maven-gh-actions-shared/compare/v4...v5)\n\n---\nupdated-dependencies:\n- dependency-name: apache/maven-gh-actions-shared/.github/workflows/stale.yml\n  dependency-version: \u00275\u0027\n  dependency-type: direct:production\n  update-type: version-update:semver-major\n...\n\nSigned-off-by: dependabot[bot] \u003csupport@github.com\u003e\nCo-authored-by: dependabot[bot] \u003c49699333+dependabot[bot]@users.noreply.github.com\u003e"
    },
    {
      "commit": "fe591022281b81060899008a6b2b47c5c2c1479f",
      "tree": "bdd9729193c6dfffc95f6787f676654a382fba3f",
      "parents": [
        "08443517b73b7094269ee190368aaf6b60cedd20"
      ],
      "author": {
        "name": "dependabot[bot]",
        "email": "49699333+dependabot[bot]@users.noreply.github.com",
        "time": "Tue Jul 14 20:53:47 2026 +0200"
      },
      "committer": {
        "name": "GitHub",
        "email": "noreply@github.com",
        "time": "Tue Jul 14 20:53:47 2026 +0200"
      },
      "message": "Bump apache/maven-gh-actions-shared/.github/workflows/pr-automation.yml (#1962)\n\nBumps [apache/maven-gh-actions-shared/.github/workflows/pr-automation.yml](https://github.com/apache/maven-gh-actions-shared) from 4 to 5.\n- [Commits](https://github.com/apache/maven-gh-actions-shared/compare/v4...v5)\n\n---\nupdated-dependencies:\n- dependency-name: apache/maven-gh-actions-shared/.github/workflows/pr-automation.yml\n  dependency-version: \u00275\u0027\n  dependency-type: direct:production\n  update-type: version-update:semver-major\n...\n\nSigned-off-by: dependabot[bot] \u003csupport@github.com\u003e\nCo-authored-by: dependabot[bot] \u003c49699333+dependabot[bot]@users.noreply.github.com\u003e"
    },
    {
      "commit": "08443517b73b7094269ee190368aaf6b60cedd20",
      "tree": "8f611fc2eb4ca53939fea69a360f940e9438667f",
      "parents": [
        "95044877bff86dec0ae1b03f7e1ec05b3353cfe9"
      ],
      "author": {
        "name": "dependabot[bot]",
        "email": "49699333+dependabot[bot]@users.noreply.github.com",
        "time": "Mon Jul 13 19:08:29 2026 +0200"
      },
      "committer": {
        "name": "GitHub",
        "email": "noreply@github.com",
        "time": "Mon Jul 13 19:08:29 2026 +0200"
      },
      "message": "Bump bouncycastleVersion from 1.84 to 1.85 (#1956)\n\nBumps `bouncycastleVersion` from 1.84 to 1.85.\n\nUpdates `org.bouncycastle:bcpg-jdk18on` from 1.84 to 1.85\n- [Changelog](https://github.com/bcgit/bc-java/blob/main/docs/releasenotes.html)\n- [Commits](https://github.com/bcgit/bc-java/commits)\n\nUpdates `org.bouncycastle:bcpkix-jdk18on` from 1.84 to 1.85\n- [Changelog](https://github.com/bcgit/bc-java/blob/main/docs/releasenotes.html)\n- [Commits](https://github.com/bcgit/bc-java/commits)\n\nUpdates `org.bouncycastle:bcprov-jdk18on` from 1.84 to 1.85\n- [Changelog](https://github.com/bcgit/bc-java/blob/main/docs/releasenotes.html)\n- [Commits](https://github.com/bcgit/bc-java/commits)\n\nUpdates `org.bouncycastle:bcutil-jdk18on` from 1.84 to 1.85\n- [Changelog](https://github.com/bcgit/bc-java/blob/main/docs/releasenotes.html)\n- [Commits](https://github.com/bcgit/bc-java/commits)\n\n---\nupdated-dependencies:\n- dependency-name: org.bouncycastle:bcpg-jdk18on\n  dependency-version: \u00271.85\u0027\n  dependency-type: direct:production\n  update-type: version-update:semver-minor\n- dependency-name: org.bouncycastle:bcpkix-jdk18on\n  dependency-version: \u00271.85\u0027\n  dependency-type: direct:production\n  update-type: version-update:semver-minor\n- dependency-name: org.bouncycastle:bcprov-jdk18on\n  dependency-version: \u00271.85\u0027\n  dependency-type: direct:production\n  update-type: version-update:semver-minor\n- dependency-name: org.bouncycastle:bcutil-jdk18on\n  dependency-version: \u00271.85\u0027\n  dependency-type: direct:production\n  update-type: version-update:semver-minor\n...\n\nSigned-off-by: dependabot[bot] \u003csupport@github.com\u003e\nCo-authored-by: dependabot[bot] \u003c49699333+dependabot[bot]@users.noreply.github.com\u003e"
    },
    {
      "commit": "95044877bff86dec0ae1b03f7e1ec05b3353cfe9",
      "tree": "7980566b8fd1bb5986bf4004aad423b5234fb144",
      "parents": [
        "5953267ee78a287740451a0dac355a4839822977"
      ],
      "author": {
        "name": "Jarek Potiuk",
        "email": "jarek@potiuk.com",
        "time": "Wed Jul 08 12:36:00 2026 +0200"
      },
      "committer": {
        "name": "Sylwester Lachiewicz",
        "email": "slachiewicz@apache.org",
        "time": "Wed Jul 08 14:49:17 2026 +0200"
      },
      "message": "Add AGENTS.md + SECURITY.md security-model pointer for scanner discoverability\n\nGenerated-by: Claude Code\n"
    },
    {
      "commit": "5953267ee78a287740451a0dac355a4839822977",
      "tree": "a52a5027ae6323330014873311d934755fcb255d",
      "parents": [
        "16bbda7e6afebb133aed63fe36ade1c850804b07"
      ],
      "author": {
        "name": "Tamas Cservenak",
        "email": "tamas@cservenak.net",
        "time": "Wed Jul 08 13:48:42 2026 +0200"
      },
      "committer": {
        "name": "GitHub",
        "email": "noreply@github.com",
        "time": "Wed Jul 08 13:48:42 2026 +0200"
      },
      "message": "Bug: Apache transport deadlock in concurrent use case (#1953)\n\nMake sure the class SSLConnectionSocketFactory is initialized early, instead lazily in ConcurrentHashMap.computeIfAbsent, as latter may cause deadlock.\n\nRefs:\n* https://github.com/quarkusio/quarkus/issues/55317\n* https://github.com/quarkusio/quarkus/pull/55345"
    },
    {
      "commit": "16bbda7e6afebb133aed63fe36ade1c850804b07",
      "tree": "6b5a491da7229014f8e0ef0d16ecb36260ad76ed",
      "parents": [
        "650f9685649f3ebfd7158b118365db70da333bda"
      ],
      "author": {
        "name": "Guillaume Nodet",
        "email": "gnodet@gmail.com",
        "time": "Tue Jul 07 16:53:56 2026 +0200"
      },
      "committer": {
        "name": "GitHub",
        "email": "noreply@github.com",
        "time": "Tue Jul 07 16:53:56 2026 +0200"
      },
      "message": "Fix potential NPEs in IpcClient and resource leak in DependencyGraphParser (#1945)\n\n- IpcClient.getJarPath(): use Class.getResource() which natively handles\n  bootstrap-loaded classes, and add null check for missing resources\n- IpcClient.receive(): capture volatile input field in local variable\n  before use to prevent NPE from concurrent close()\n- IpcClient.getAddress(): capture volatile socket field in local variable\n  with null check to prevent NPE during concurrent close()\n- DependencyGraphParser.parseMultiResource(): wrap BufferedReader in\n  try-with-resources to prevent stream leak on exception"
    },
    {
      "commit": "650f9685649f3ebfd7158b118365db70da333bda",
      "tree": "95b1a8daae9cc02e966bc39a53b8ff9f37515468",
      "parents": [
        "f9d2c8395e217796eeb5e69fda0bf2fde0960d93"
      ],
      "author": {
        "name": "Tamas Cservenak",
        "email": "tamas@cservenak.net",
        "time": "Sun Jul 05 22:27:35 2026 +0200"
      },
      "committer": {
        "name": "GitHub",
        "email": "noreply@github.com",
        "time": "Sun Jul 05 22:27:35 2026 +0200"
      },
      "message": "Bug: Jetty transport used wrong config (#1948)"
    },
    {
      "commit": "f9d2c8395e217796eeb5e69fda0bf2fde0960d93",
      "tree": "beff1db10673fbc8a08482db87bfc032e1537c65",
      "parents": [
        "54197d564aa53983d9e37151d02f80704a7a0093"
      ],
      "author": {
        "name": "Konrad Windszus",
        "email": "kwin@apache.org",
        "time": "Thu Jul 02 15:21:52 2026 +0200"
      },
      "committer": {
        "name": "Konrad Windszus",
        "email": "konrad@windszus.net",
        "time": "Thu Jul 02 16:23:45 2026 +0200"
      },
      "message": "Limit internal retries to 1 with Java 26+\n\nThis only affects IT and Java26+. The internal retry handling changed\nwith Java 26\n(https://github.com/openjdk/jdk/commit/e8db14f584fa92db170e056bc68074ccabae82c9#diff-41e3c3f66a6d78612e230f2546ac15e3f82619efe333a731b64f59a9e4991816).\nPreviously for connection closed exceptions there were always 2 attempts\nwhile with Java 26 this defaults to system property\n\"jdk.httpclient.redirects.retrylimit\" now."
    },
    {
      "commit": "54197d564aa53983d9e37151d02f80704a7a0093",
      "tree": "45f1ef64b3b9d0418c34e87cc81118d2e3591044",
      "parents": [
        "fd6984937ffc4f99a48459b912c33c90cf629ad6"
      ],
      "author": {
        "name": "Tamas Cservenak",
        "email": "tamas@cservenak.net",
        "time": "Tue Jun 30 09:52:32 2026 +0200"
      },
      "committer": {
        "name": "Tamas Cservenak",
        "email": "tamas@cservenak.net",
        "time": "Tue Jun 30 09:52:32 2026 +0200"
      },
      "message": "[maven-release-plugin] prepare for next development iteration\n"
    },
    {
      "commit": "fd6984937ffc4f99a48459b912c33c90cf629ad6",
      "tree": "60801aeeea3d586454fa393c8e80002adae5e924",
      "parents": [
        "cf2eaeff7dab4f967538c21470de138fe11198b4"
      ],
      "author": {
        "name": "Tamas Cservenak",
        "email": "tamas@cservenak.net",
        "time": "Tue Jun 30 09:52:04 2026 +0200"
      },
      "committer": {
        "name": "Tamas Cservenak",
        "email": "tamas@cservenak.net",
        "time": "Tue Jun 30 09:52:04 2026 +0200"
      },
      "message": "[maven-release-plugin] prepare release maven-resolver-2.0.20\n"
    },
    {
      "commit": "cf2eaeff7dab4f967538c21470de138fe11198b4",
      "tree": "41b09f1062814d9fa8b02cd11e9d7f12973d7311",
      "parents": [
        "d331083b8c1fdfd3f37fc44d8e9152fb5b5f960f"
      ],
      "author": {
        "name": "Tamas Cservenak",
        "email": "tamas@cservenak.net",
        "time": "Mon Jun 29 22:33:16 2026 +0200"
      },
      "committer": {
        "name": "GitHub",
        "email": "noreply@github.com",
        "time": "Mon Jun 29 22:33:16 2026 +0200"
      },
      "message": "Put PCR aside for now (#1942)\n\nIt\u0027s proven a bit problematic, and memory hungry,\nwhile the promise of O(N) over O(N^2) is cool."
    },
    {
      "commit": "d331083b8c1fdfd3f37fc44d8e9152fb5b5f960f",
      "tree": "21c6b036b34be9d6bb82b58d78b7d4d31ebbfe36",
      "parents": [
        "46acf1298ec42bdc33544b127e322bd553305156"
      ],
      "author": {
        "name": "Guillaume Nodet",
        "email": "gnodet@gmail.com",
        "time": "Mon Jun 29 21:45:03 2026 +0200"
      },
      "committer": {
        "name": "GitHub",
        "email": "noreply@github.com",
        "time": "Mon Jun 29 21:45:03 2026 +0200"
      },
      "message": "Reduce PathConflictResolver memory and auto-select resolver (#1938)\n\n## Summary\n\nImprovements to `PathConflictResolver` to prevent OOM and StackOverflow on large dependency graphs, plus allocation and collection-sizing optimizations:\n\n### Memory \u0026 safety improvements\n\n1. **Auto-selection heuristic** (new default `\"auto\"` mode): walks the dependency tree counting total nodes (including diamond-expanded duplicates) with early-exit optimization. Falls back to `ClassicConflictResolver` when the estimated Path tree memory exceeds 25% of available heap. This correctly handles the pathological case where diamond dependencies cause the Path tree to be 100-150× larger than the unique node count.\n\n2. **Lazy children lists**: `Path.children` starts as `null` (leaf nodes never allocate a list). Initialized in `addChildren()` with exact capacity. Saves ~40 bytes per leaf node (typically 60-70% of all nodes).\n\n3. **Out-of-scope flag**: replaces removal from `LinkedHashSet` partitions with a boolean `outOfScope` flag. Partitions use `ArrayList` instead of `LinkedHashSet`, avoiding ~48 bytes/entry of HashMap.Node overhead.\n\n4. **Iterative `gatherCRNodes` and `moveOutOfScope`**: both replaced recursive DFS with explicit `ArrayList` stacks to avoid `StackOverflowError` on deep dependency chains.\n\n5. **Partition compaction**: after filtering active paths for each conflict group, the partition entry is replaced with the filtered list, releasing references to out-of-scope paths and their detached subtrees for GC during resolution instead of retaining them until the end.\n\n6. **Children nulling on out-of-scope**: `moveOutOfScope()` nulls children references on marked nodes, accelerating GC of detached subtrees.\n\n### Allocation \u0026 performance optimizations\n\n7. **Allocation-free artifact comparisons**: replaced `ArtifactIdUtils.toId()` / `toVersionlessId()` + `String.equals()` with `equalsId()` / `equalsVersionlessId()` in `push()` and `isDirectDependencyOnPathToRoot()`.\n\n8. **Eliminate string concatenation in `relatedSiblingsCount()`**: compare `groupId`/`artifactId` fields directly.\n\n9. **Pre-sized `activePaths` / `items` lists**: initialized with `allPaths.size()` capacity.\n\n10. **Right-sized `partitions` / `resolvedIds` HashMaps**: initialized with exact capacity from `sortedConflictIds.size()`.\n\n11. **Pooled `ScopeContext`**: single mutable instance on `State`, reset and reused.\n\n12. **Optimized `isDirectDependencyOnPathToRoot()`**: walks directly to the depth-1 ancestor.\n\n13. **Removed dead recursive `push()` code**: `push()` is always called with `levels\u003d0`.\n\n14. **Inline stats tracking**: `conflictItemCount` tracked during the main loop.\n\n## Benchmark results\n\nTested with a real-world 814-module project with heavy inter-module dependencies:\n\n| Configuration | Heap | Result |\n|---|---|---|\n| **Baseline** (master, `path` default) | 512m | **OOM** (125s of GC thrashing) |\n| **Baseline** (master, `path` default) | 1g | **OOM** (126s) |\n| **Baseline** (master, `path` default) | 2g | **OOM** (267s) |\n| **Baseline** (master, `path` default) | 4g | **OOM** (424s) |\n| **Patched** (`path` forced) | 4g | ✅ OK (214s) |\n| **Patched** (`classic` forced) | 384m | ✅ OK (183s) |\n| **Patched** (`classic` forced) | 512m | ✅ OK (153-163s, 3 runs) |\n| **Patched** (`auto` default) | 384m | ✅ OK (222s) |\n| **Patched** (`auto` default) | 512m | ✅ OK (165-210s, 3 runs) |\n\n**Key findings:**\n- The baseline `PathConflictResolver` **cannot resolve this project at any heap size** (OOM even at 4GB)\n- The root cause: diamond dependencies cause the Path tree to explode. A single module with 7,522 unique nodes produces **1,190,821 tree nodes** (158× expansion factor)\n- The old heuristic used `conflictIds.size()` (unique nodes) — estimated ~1MB when the actual Path tree was ~227MB\n- The new heuristic walks the tree counting actual nodes with early-exit, correctly falling back to `ClassicConflictResolver` for large graphs\n- With auto-selection, the patched resolver **succeeds at 384MB heap** where the baseline fails at 4GB\n\n## Test plan\n\n- [x] All 443 tests pass (438 original + 5 new auto-selection tests)\n- [x] New tests cover: auto mode, explicit path/classic config dispatch, unknown config rejection, default config behavior\n- [x] Benchmarked with 814-module real-world reproducer — confirms OOM fix and correct auto-selection"
    },
    {
      "commit": "46acf1298ec42bdc33544b127e322bd553305156",
      "tree": "8b4c9afda2106f475ff8de37c6f66e04c53fd594",
      "parents": [
        "62948bc845bf5bdad4d608ff3251714ccce84abf"
      ],
      "author": {
        "name": "Guillaume Nodet",
        "email": "gnodet@gmail.com",
        "time": "Mon Jun 29 21:43:12 2026 +0200"
      },
      "committer": {
        "name": "GitHub",
        "email": "noreply@github.com",
        "time": "Mon Jun 29 21:43:12 2026 +0200"
      },
      "message": "Fix dependency selector cache regression in DF collector (#1941)\n\n## Summary\n\n`ScopeDependencySelector` and `OptionalDependencySelector` (in `impl.scope` package) always create new instances in `deriveChildSelector()`, incrementing `depth` at every level. Since `depth` is part of `equals()`/`hashCode()`, every tree depth produces a unique selector, which makes the `DataPool`/`GraphKey` cache in the DF dependency collector miss on every lookup across depths.\n\nThis causes **exponential node growth** in the DF collector for large dependency trees. In a benchmark with a large multi-module project:\n\n| Configuration | Node count |\n|---|---|\n| Resolver 1.9.27 (Maven 3.9.16), DF collector | 1,054,704 |\n| Resolver 2.0.x (Maven 3.10.x), BF collector | 1,915,842 |\n| Resolver 2.0.x (Maven 3.10.x), DF collector | 9,893,981 |\n\nThe DF collector\u0027s 9.4x node increase is caused by cache misses cascading exponentially — each miss triggers full recursion, discovering more nodes that also miss the cache.\n\n## Root cause\n\nThe old selectors (resolver 1.x, in `util.graph.selector` package) returned `this` from `deriveChildSelector()` once their behavior stabilized:\n\n- `ScopeDependencySelector`: returned `this` once `transitive\u003dtrue` (after depth 1)\n- `OptionalDependencySelector`: returned `this` once `depth \u003e\u003d 2`\n\nThe `AndDependencySelector` already optimizes for this pattern (line 119): when all child selectors return `this` (reference equality), the `AndDependencySelector` also returns `this`. This meant the entire composite selector was the **same instance** at all depths 2+, enabling cache hits in the `GraphKey`.\n\nThe new `impl.scope` selectors never return `this` — they always create new instances with `depth + 1`, breaking this optimization chain.\n\n## Fix\n\nBoth selectors now return `this` from `deriveChildSelector()` once `depth \u003e\u003d applyFrom` (the point after which their `selectDependency()` behavior no longer changes with depth). For `ScopeDependencySelector`, the only exception is `depth \u003d\u003d applyTo` where behavior transitions from \"filter by scope\" to \"accept all\".\n\nFor the default Maven 3.10.x configuration (`ScopeDependencySelector.legacy(null, [\"test\", \"provided\"])`), this means the selector stabilizes at depth 2, matching the old resolver 1.x behavior.\n\n_Claude Code on behalf of Guillaume Nodet_"
    },
    {
      "commit": "62948bc845bf5bdad4d608ff3251714ccce84abf",
      "tree": "ff89ee3e18db9be8f00df6a92125f8602cc10054",
      "parents": [
        "89cd11d6d1e073fd1d2de5399a0b9bd17aa9f863"
      ],
      "author": {
        "name": "dependabot[bot]",
        "email": "49699333+dependabot[bot]@users.noreply.github.com",
        "time": "Mon Jun 29 11:29:10 2026 +0200"
      },
      "committer": {
        "name": "GitHub",
        "email": "noreply@github.com",
        "time": "Mon Jun 29 11:29:10 2026 +0200"
      },
      "message": "Bump org.apache.maven:maven-parent from 48 to 49 (#1939)\n\nBumps [org.apache.maven:maven-parent](https://github.com/apache/maven-parent) from 48 to 49.\n- [Release notes](https://github.com/apache/maven-parent/releases)\n- [Commits](https://github.com/apache/maven-parent/commits)\n\n---\nupdated-dependencies:\n- dependency-name: org.apache.maven:maven-parent\n  dependency-version: \u002749\u0027\n  dependency-type: direct:production\n  update-type: version-update:semver-major\n...\n\nSigned-off-by: dependabot[bot] \u003csupport@github.com\u003e\nCo-authored-by: dependabot[bot] \u003c49699333+dependabot[bot]@users.noreply.github.com\u003e"
    },
    {
      "commit": "89cd11d6d1e073fd1d2de5399a0b9bd17aa9f863",
      "tree": "ce185f26bb31eb883d57230e95f1e022e4c26528",
      "parents": [
        "47c436f8fecfd1a924ed06f3261686c09c937f7f"
      ],
      "author": {
        "name": "Guillaume Nodet",
        "email": "gnodet@gmail.com",
        "time": "Sat Jun 27 16:03:50 2026 +0200"
      },
      "committer": {
        "name": "GitHub",
        "email": "noreply@github.com",
        "time": "Sat Jun 27 16:03:50 2026 +0200"
      },
      "message": "Fix thread contention in GenericVersionScheme and WeakInternPool (#1937)\n\n## Problem\n\nPR #1902 introduced `synchronized(versionCache)` and `synchronized(this.map)` blocks around compound cache operations to fix a thread-safety issue with `computeIfAbsent()` on `synchronizedMap(WeakHashMap)`. While correct, this serialized all threads on hot paths, causing a **2x build time regression** for Quarkus (~6min → ~12min).\n\n### Root cause analysis\n\n`Collections.synchronizedMap(new WeakHashMap\u003c\u003e())` wraps each individual method (`get`, `put`) in `synchronized(mutex)`, but does NOT make compound operations like `computeIfAbsent()` atomic. PR #1902 fixed this by adding outer `synchronized` blocks — correct but serializing.\n\nThe original pre-#1902 code used separate `get()` + `put()` calls where each individually acquires/releases the lock for microseconds. The compound race is **benign for a cache** — at worst a duplicate value is created and one wins the put.\n\n## Solution\n\n### 1. `ConcurrentWeakCache` — new lightweight concurrent cache\n\nIntroduces `ConcurrentWeakCache\u003cK,V\u003e` — a stripped-down version of maven-impl\u0027s `Cache`, optimized for hot-path performance:\n\n- **Lock-free reads** — `ConcurrentHashMap.get()` is a volatile read, no lock acquisition\n- **Zero allocation on `get()`** — uses a `ThreadLocal` reusable lookup key instead of allocating a new wrapper per read (the main perf issue with the full `Cache` class)\n- **O(1) stale entry cleanup** — identity-based removal from `ReferenceQueue` instead of `entrySet().removeIf()` full-map scan\n- **Weak keys** — entries GC\u0027d when key is no longer strongly referenced (same as `WeakHashMap`)\n- **Weak values** — values also held via `WeakReference`\n\n### 2. `PathConflictResolver` memory explosion fix\n\nThe `PathConflictResolver` had an O(n²) memory issue from copying `HashSet\u003cObject\u003e conflictIdsSinceRoot` at every graph node. Replaced with:\n- Parent-chain walk (`hasConflictIdOnPathToRoot()`) — O(depth) per check, no copying\n- `LinkedHashSet` partitions — O(1) removal instead of O(n) `ArrayList.remove()`\n\n### 3. Tracking file read cache\n\n`EnhancedLocalRepositoryManager.readRepos()` re-reads `_remote.repositories` tracking files from disk (with file locking) on every artifact resolution, even for artifacts in the same directory. In a primed build, this causes thousands of redundant file reads with synchronized blocks and FileLock acquisition.\n\nAdded a `ConcurrentHashMap\u003cPath, Properties\u003e` cache keyed by tracking file path. Multiple artifacts in the same directory (e.g. jar + pom) share the same tracking file, so the cache hit rate is high. The cache is invalidated (not updated) on writes via `addRepo()` to avoid a race where two concurrent writes could reorder their cache puts.\n\n### 4. Lock-free fast path for `NamedLockFactorySupport`\n\n`getLockAndRefTrack()` used `ConcurrentHashMap.compute()` on every call, which takes a per-bucket exclusive lock even when the holder already exists. In the common case (lock exists, just increment refcount), this serialized all threads hashing to the same bucket.\n\nAdded a lock-free fast path: `ConcurrentHashMap.get()` (volatile read) + `tryIncRef()` (CAS loop on `AtomicInteger`). Only falls back to `compute()` when the holder is absent or being closed.\n\nThe close/acquire race is handled by a CAS sentinel: `closeLock()` marks the holder as closed (CAS refcount `0 → MIN_VALUE`) before destroying it. `tryIncRef()` rejects `refcount ≤ 0`, preventing revival of a destroyed lock.\n\n### 5. `InhibitingNameMapper` stream→loop conversion\n\nReplaced `Stream.filter().collect()` with imperative loops and added empty-list short-circuit to skip the filtering entirely when no `LockingInhibitor`s are registered (the common case).\n\n### 6. `FileLockNamedLockFactory` FileChannel reuse\n\n`destroyLock()` was closing the `FileChannel` on every lock release, forcing a new `open()` syscall on every lock acquisition. Since the lock factory is session-scoped, the channels can be kept open for reuse across lock acquire/release cycles. Channels are now closed only during factory `shutdown()`.\n\n## Profiling results (async-profiler wall-clock, 5ms interval)\n\n### End-to-end build time (Quarkus primed build, 8-thread)\n\n| Configuration | Build time | vs Baseline |\n|---|---|---|\n| Baseline (2.0.19-SNAPSHOT) | 169.7s | — |\n| + tracking file cache | ~160s | −6% |\n| + lock-free getLockAndRefTrack | 149.1s | −12% |\n| **+ FileChannel reuse + InhibitingNameMapper** | **93.5s** | **−45%** |\n\n### Method-level sample comparison (baseline → all patches)\n\n| Method | Baseline | Patched | Change |\n|---|---|---|---|\n| `EnhancedLocalRepositoryManager.find()` | 275 | 109 | **−60%** |\n| `FileLockNamedLockFactory.createLock()` | 246 | 107 | **−56%** |\n| `readRepos()` | 208 | 71 | **−66%** |\n| `LegacyTrackingFileManager.read()` | 201 | 54 | **−73%** |\n| `Retry.retry()` | 167 | 86 | **−49%** |\n| `InhibitingNameMapper.nameLocks()` | 141 | 85 | **−40%** |\n| `getLockAndRefTrack()` | 128 | 67 | **−48%** |\n| `destroyLock()` | 46 | 0 | **−100%** |\n| `mutex()` (String.intern lock) | 46 | 0 | **eliminated** |\n\n### ConcurrentWeakCache microbenchmark (4 threads, 8M ops/iteration)\n\n| Approach | Version Cache | Intern Pool |\n|---|---|---|\n| **Master** (synchronized blocks from #1902) | 1668ms (4.8M ops/sec) | 916ms (8.7M ops/sec) |\n| Original synchronizedMap (pre-#1902) | 360ms (22.2M ops/sec) | 457ms (17.5M ops/sec) |\n| **ConcurrentWeakCache (this PR)** | **155ms (51.6M ops/sec)** | **176ms (45.5M ops/sec)** |\n\n**10.8x faster than master** for version parsing, **5.2x faster** for artifact interning, while preserving weak reference semantics for GC-friendly memory behavior.\n\n## Files changed\n\n- `ConcurrentWeakCache.java` — new lightweight concurrent cache with weak keys/values\n- `GenericVersionScheme.java` — use `ConcurrentWeakCache` for version parsing cache\n- `DataPool.java` — use `ConcurrentWeakCache` for `WeakInternPool`\n- `PathConflictResolver.java` — fix O(n²) memory from HashSet copying\n- `EnhancedLocalRepositoryManager.java` — cache tracking file reads to eliminate redundant disk I/O\n- `NamedLockFactorySupport.java` — lock-free fast path for ref-counted lock acquisition\n- `InhibitingNameMapper.java` — stream→loop conversion with empty-list short-circuit\n- `FileLockNamedLockFactory.java` — FileChannel reuse across lock lifecycle"
    },
    {
      "commit": "47c436f8fecfd1a924ed06f3261686c09c937f7f",
      "tree": "b9cffd05566ba57800cb6a69f3674d5c85c6e0e7",
      "parents": [
        "526b6e07d786f1ff7180766d3934250c760ff0c6"
      ],
      "author": {
        "name": "dependabot[bot]",
        "email": "49699333+dependabot[bot]@users.noreply.github.com",
        "time": "Thu Jun 25 12:22:59 2026 +0200"
      },
      "committer": {
        "name": "GitHub",
        "email": "noreply@github.com",
        "time": "Thu Jun 25 12:22:59 2026 +0200"
      },
      "message": "Bump roasterVersion from 2.31.0.Final to 2.31.1.Final (#1935)\n\nBumps `roasterVersion` from 2.31.0.Final to 2.31.1.Final.\n\nUpdates `org.jboss.forge.roaster:roaster-api` from 2.31.0.Final to 2.31.1.Final\n- [Release notes](https://github.com/forge/roaster/releases)\n- [Commits](https://github.com/forge/roaster/compare/2.31.0.Final...2.31.1.Final)\n\nUpdates `org.jboss.forge.roaster:roaster-jdt` from 2.31.0.Final to 2.31.1.Final\n\n---\nupdated-dependencies:\n- dependency-name: org.jboss.forge.roaster:roaster-api\n  dependency-version: 2.31.1.Final\n  dependency-type: direct:production\n  update-type: version-update:semver-patch\n- dependency-name: org.jboss.forge.roaster:roaster-jdt\n  dependency-version: 2.31.1.Final\n  dependency-type: direct:production\n  update-type: version-update:semver-patch\n...\n\nSigned-off-by: dependabot[bot] \u003csupport@github.com\u003e\nCo-authored-by: dependabot[bot] \u003c49699333+dependabot[bot]@users.noreply.github.com\u003e"
    },
    {
      "commit": "526b6e07d786f1ff7180766d3934250c760ff0c6",
      "tree": "9282c720cb6d48818ed8eb921e18b4df58795429",
      "parents": [
        "556461f11242653b87794d2a3a038163ea2b584c"
      ],
      "author": {
        "name": "dependabot[bot]",
        "email": "49699333+dependabot[bot]@users.noreply.github.com",
        "time": "Thu Jun 25 12:22:30 2026 +0200"
      },
      "committer": {
        "name": "GitHub",
        "email": "noreply@github.com",
        "time": "Thu Jun 25 12:22:30 2026 +0200"
      },
      "message": "Bump sisuVersion from 1.0.0 to 1.0.1 (#1936)\n\nBumps `sisuVersion` from 1.0.0 to 1.0.1.\n\nUpdates `org.eclipse.sisu:org.eclipse.sisu.inject` from 1.0.0 to 1.0.1\n- [Release notes](https://github.com/eclipse-sisu/sisu-project/releases)\n- [Changelog](https://github.com/eclipse-sisu/sisu-project/blob/main/RELEASE.md)\n- [Commits](https://github.com/eclipse-sisu/sisu-project/compare/releases/1.0.0...releases/1.0.1)\n\nUpdates `org.eclipse.sisu:org.eclipse.sisu.plexus` from 1.0.0 to 1.0.1\n- [Release notes](https://github.com/eclipse-sisu/sisu-project/releases)\n- [Changelog](https://github.com/eclipse-sisu/sisu-project/blob/main/RELEASE.md)\n- [Commits](https://github.com/eclipse-sisu/sisu-project/compare/releases/1.0.0...releases/1.0.1)\n\n---\nupdated-dependencies:\n- dependency-name: org.eclipse.sisu:org.eclipse.sisu.inject\n  dependency-version: 1.0.1\n  dependency-type: direct:production\n  update-type: version-update:semver-patch\n- dependency-name: org.eclipse.sisu:org.eclipse.sisu.plexus\n  dependency-version: 1.0.1\n  dependency-type: direct:production\n  update-type: version-update:semver-patch\n...\n\nSigned-off-by: dependabot[bot] \u003csupport@github.com\u003e\nCo-authored-by: dependabot[bot] \u003c49699333+dependabot[bot]@users.noreply.github.com\u003e"
    },
    {
      "commit": "556461f11242653b87794d2a3a038163ea2b584c",
      "tree": "a7ffdf87563d8c339501d39a92b14cf38aca0913",
      "parents": [
        "69b6cf8894b37136295f56ed6b4c2618d72ecd45"
      ],
      "author": {
        "name": "Tamas Cservenak",
        "email": "tamas@cservenak.net",
        "time": "Wed Jun 24 15:37:57 2026 +0200"
      },
      "committer": {
        "name": "Tamas Cservenak",
        "email": "tamas@cservenak.net",
        "time": "Wed Jun 24 15:37:57 2026 +0200"
      },
      "message": "[maven-release-plugin] prepare for next development iteration\n"
    },
    {
      "commit": "69b6cf8894b37136295f56ed6b4c2618d72ecd45",
      "tree": "20ebf0a393b0c5bec09e9e64cf641b16136910a7",
      "parents": [
        "331895b33a6886d532d77b27cb70c1a8e1caff6f"
      ],
      "author": {
        "name": "Tamas Cservenak",
        "email": "tamas@cservenak.net",
        "time": "Wed Jun 24 15:37:20 2026 +0200"
      },
      "committer": {
        "name": "Tamas Cservenak",
        "email": "tamas@cservenak.net",
        "time": "Wed Jun 24 15:37:20 2026 +0200"
      },
      "message": "[maven-release-plugin] prepare release maven-resolver-2.0.19\n"
    },
    {
      "commit": "331895b33a6886d532d77b27cb70c1a8e1caff6f",
      "tree": "5370e87afdcef93f1081a17cd163d1a39cef4724",
      "parents": [
        "96b2a2aa67675e4725c6d6f7dd08e1ab941c4d65"
      ],
      "author": {
        "name": "Tamas Cservenak",
        "email": "tamas@cservenak.net",
        "time": "Wed Jun 24 12:06:01 2026 +0200"
      },
      "committer": {
        "name": "GitHub",
        "email": "noreply@github.com",
        "time": "Wed Jun 24 12:06:01 2026 +0200"
      },
      "message": "Get rid of BND warnings (#1933)\n\nBy properly formatting bnd parameters (follow emitted advice, add trailing `:`)."
    },
    {
      "commit": "96b2a2aa67675e4725c6d6f7dd08e1ab941c4d65",
      "tree": "4844b2fe46b5ff852729acee215dbb4c5de5ee91",
      "parents": [
        "c346720ebfb1ceba91d878f6a20b1935cbe8abcb"
      ],
      "author": {
        "name": "dependabot[bot]",
        "email": "49699333+dependabot[bot]@users.noreply.github.com",
        "time": "Fri Jun 19 10:15:08 2026 +0200"
      },
      "committer": {
        "name": "GitHub",
        "email": "noreply@github.com",
        "time": "Fri Jun 19 10:15:08 2026 +0200"
      },
      "message": "Bump org.redisson:redisson from 4.6.0 to 4.6.1 (#1932)\n\nBumps [org.redisson:redisson](https://github.com/redisson/redisson) from 4.6.0 to 4.6.1.\n- [Release notes](https://github.com/redisson/redisson/releases)\n- [Changelog](https://github.com/redisson/redisson/blob/master/CHANGELOG.md)\n- [Commits](https://github.com/redisson/redisson/compare/redisson-4.6.0...redisson-4.6.1)\n\n---\nupdated-dependencies:\n- dependency-name: org.redisson:redisson\n  dependency-version: 4.6.1\n  dependency-type: direct:production\n  update-type: version-update:semver-patch\n...\n\nSigned-off-by: dependabot[bot] \u003csupport@github.com\u003e\nCo-authored-by: dependabot[bot] \u003c49699333+dependabot[bot]@users.noreply.github.com\u003e"
    },
    {
      "commit": "c346720ebfb1ceba91d878f6a20b1935cbe8abcb",
      "tree": "e97fe59380fb566f6a0ae2665874fa918dca7ffc",
      "parents": [
        "35d0d46691fc2fb864762fde61b2fef83d27d8dc"
      ],
      "author": {
        "name": "Tamas Cservenak",
        "email": "tamas@cservenak.net",
        "time": "Wed Jun 17 21:45:29 2026 +0200"
      },
      "committer": {
        "name": "GitHub",
        "email": "noreply@github.com",
        "time": "Wed Jun 17 21:45:29 2026 +0200"
      },
      "message": "Deps: Jetty 12.1.10 (#1930)\n\nUpdate Jetty version, server used in HTTP tests\nand client used in Jetty transport."
    },
    {
      "commit": "35d0d46691fc2fb864762fde61b2fef83d27d8dc",
      "tree": "cc03f7f4cb2eb2d0548f22fe1a90f239ded847b0",
      "parents": [
        "e66df503d73c9f5f19abe316b1ec39340750809b"
      ],
      "author": {
        "name": "Tamas Cservenak",
        "email": "tamas@cservenak.net",
        "time": "Tue Jun 16 13:32:10 2026 +0200"
      },
      "committer": {
        "name": "GitHub",
        "email": "noreply@github.com",
        "time": "Tue Jun 16 13:32:10 2026 +0200"
      },
      "message": "Align generators (#1929)\n\nAfter #1902 only one had changes, but they always used\ntogether.\n\nAlso, rather make `close()` idempotent than synchronized."
    },
    {
      "commit": "e66df503d73c9f5f19abe316b1ec39340750809b",
      "tree": "637d6d51f587e5723b0b2797b02aeff9cf26e61f",
      "parents": [
        "5e928d28eb3a1437fae38764753ee9d75f7a49c6"
      ],
      "author": {
        "name": "Guillaume Nodet",
        "email": "gnodet@gmail.com",
        "time": "Sun Jun 07 09:47:24 2026 +0000"
      },
      "committer": {
        "name": "Guillaume Nodet",
        "email": "gnodet@gmail.com",
        "time": "Tue Jun 16 12:10:25 2026 +0200"
      },
      "message": "Fix GnupgSignatureArtifactGenerator — use CopyOnWriteArrayList for artifacts\n\nThe signatureTempFiles field was changed to CopyOnWriteArrayList for\nthread safety, but the artifacts field (also mutated via addAll in\ngenerate()) was left as a plain ArrayList.\n\nChange artifacts to CopyOnWriteArrayList for consistency, since both\nfields are mutated and iterated in the same methods.\n\n"
    },
    {
      "commit": "5e928d28eb3a1437fae38764753ee9d75f7a49c6",
      "tree": "2c0eecd935785dfd1a3d1e7fd3ff16e89884be91",
      "parents": [
        "d9a1b876578dc8b1ead736bc3c5753a35954d9c8"
      ],
      "author": {
        "name": "Guillaume Nodet",
        "email": "gnodet@gmail.com",
        "time": "Sun Jun 07 09:46:48 2026 +0000"
      },
      "committer": {
        "name": "Guillaume Nodet",
        "email": "gnodet@gmail.com",
        "time": "Tue Jun 16 12:10:25 2026 +0200"
      },
      "message": "Fix Results — synchronize read methods for visibility\n\nThe write paths addException() and addCycle() are synchronized but\ngetResult() and getErrorPath() were not, so readers could observe\nstale data without a happens-before edge from the writer.\n\nMake both getter methods synchronized to establish proper visibility\nguarantees for cross-thread reads.\n\n"
    },
    {
      "commit": "d9a1b876578dc8b1ead736bc3c5753a35954d9c8",
      "tree": "df90067518d21f42306755eb092950ded6fe1391",
      "parents": [
        "7fa7741a9889d98e7d0ed1e8543ab1796e01b1ad"
      ],
      "author": {
        "name": "Guillaume Nodet",
        "email": "gnodet@gmail.com",
        "time": "Sun Jun 07 09:45:45 2026 +0000"
      },
      "committer": {
        "name": "Guillaume Nodet",
        "email": "gnodet@gmail.com",
        "time": "Tue Jun 16 12:10:25 2026 +0200"
      },
      "message": "Fix WeakInternPool — synchronize compute on map\n\nCollections.synchronizedMap does not make compute() atomic; the\ndefault Map.compute implementation performs a non-atomic read-modify\nsequence, risking concurrent structural modification of the underlying\nWeakHashMap.\n\nWrap the compute() call in synchronized(map) to use the same monitor\nthat synchronizedMap uses internally.\n\n"
    },
    {
      "commit": "7fa7741a9889d98e7d0ed1e8543ab1796e01b1ad",
      "tree": "450735e46e05775984a074825891e91b587db16e",
      "parents": [
        "dc2c84ff9de73ed5d707b7f5c1f3e23469d9b615"
      ],
      "author": {
        "name": "Guillaume Nodet",
        "email": "gnodet@gmail.com",
        "time": "Sun Jun 07 09:44:41 2026 +0000"
      },
      "committer": {
        "name": "Guillaume Nodet",
        "email": "gnodet@gmail.com",
        "time": "Tue Jun 16 12:10:25 2026 +0200"
      },
      "message": "Fix GenericVersionScheme — synchronize computeIfAbsent on versionCache\n\nCollections.synchronizedMap does not make computeIfAbsent atomic;\nthe default Map.computeIfAbsent implementation performs a non-atomic\nget-then-put sequence, risking concurrent structural modification of\nthe underlying WeakHashMap.\n\nWrap the computeIfAbsent call in synchronized(versionCache) to use\nthe same monitor that synchronizedMap uses internally.\n\n"
    },
    {
      "commit": "dc2c84ff9de73ed5d707b7f5c1f3e23469d9b615",
      "tree": "a787a4965df74175ebe45834692301511325341f",
      "parents": [
        "8dcd69c4edacb27b710ebaf526e75c0de100fc84"
      ],
      "author": {
        "name": "Guillaume Nodet",
        "email": "gnodet@gmail.com",
        "time": "Sun Jun 07 09:43:56 2026 +0000"
      },
      "committer": {
        "name": "Guillaume Nodet",
        "email": "gnodet@gmail.com",
        "time": "Tue Jun 16 12:10:25 2026 +0200"
      },
      "message": "Fix IpcServer unlock — replace TOCTOU isEmpty+remove with atomic compute\n\nThe unlock() path had a race: after checking l.isEmpty(), another\nthread could computeIfAbsent and re-use the same Lock object, then\nthe remove(l.key, l) would remove a Lock that now has holders.\n\nReplace the two-step isEmpty() check + remove() with a single\nlocks.compute() call that atomically checks emptiness and removes.\n\n"
    },
    {
      "commit": "8dcd69c4edacb27b710ebaf526e75c0de100fc84",
      "tree": "6d8ee1ff1d865cb0a770965effce1c012fb73e3b",
      "parents": [
        "4fa61b8b38732ce9f578762a10b3c77f2eef4117"
      ],
      "author": {
        "name": "Guillaume Nodet",
        "email": "gnodet@gmail.com",
        "time": "Sun Jun 07 09:43:21 2026 +0000"
      },
      "committer": {
        "name": "Guillaume Nodet",
        "email": "gnodet@gmail.com",
        "time": "Tue Jun 16 12:10:25 2026 +0200"
      },
      "message": "Fix SmartExecutor — add RejectedExecutionException fallback to Callable overloads\n\nPooled.submit(Callable) and Limited.submit(Callable) did not catch\nRejectedExecutionException, unlike their Runnable counterparts. On\nrejection, Pooled would let the REE propagate with a never-completed\nfuture, and Limited would additionally leak a semaphore permit.\n\nApply the same try-catch-fallback pattern: on rejection, run the\ncallable on the caller thread and complete the future inline.\n\n"
    },
    {
      "commit": "4fa61b8b38732ce9f578762a10b3c77f2eef4117",
      "tree": "67d17bc1168c80a937ab470c7b56c427acdfaf13",
      "parents": [
        "cc51f3385098ac928a21994a57e509c9461ce79a"
      ],
      "author": {
        "name": "Guillaume Nodet",
        "email": "gnodet@gmail.com",
        "time": "Sun Jun 07 07:08:59 2026 +0000"
      },
      "committer": {
        "name": "Guillaume Nodet",
        "email": "gnodet@gmail.com",
        "time": "Tue Jun 16 12:10:25 2026 +0200"
      },
      "message": "Fix GnupgSignatureArtifactGenerator — use CopyOnWriteArrayList\n\nF-35: Replace plain ArrayList with CopyOnWriteArrayList for\nsignatureTempFiles as a defensive measure against potential\nconcurrent access between generate() and close().\n\n"
    },
    {
      "commit": "cc51f3385098ac928a21994a57e509c9461ce79a",
      "tree": "868e373a5b40ca51cf640895d81f6eeebfc787f1",
      "parents": [
        "99e7e8dd3e0cf8a6dc8c8ea6b04335a330dbe40b"
      ],
      "author": {
        "name": "Guillaume Nodet",
        "email": "gnodet@gmail.com",
        "time": "Sun Jun 07 07:07:26 2026 +0000"
      },
      "committer": {
        "name": "Guillaume Nodet",
        "email": "gnodet@gmail.com",
        "time": "Tue Jun 16 12:10:25 2026 +0200"
      },
      "message": "Fix MinioTransporter implPut — close InputStream from task\n\nF-33: Wrap task.newInputStream() in try-with-resources so the stream\nis properly closed after Files.copy(), preventing resource leaks on\nboth normal and error paths.\n\n"
    },
    {
      "commit": "99e7e8dd3e0cf8a6dc8c8ea6b04335a330dbe40b",
      "tree": "4fed01f9a91c04c6419f6f4819b4d1924bcf9d95",
      "parents": [
        "42339126041d3050407648587f12557009093c70"
      ],
      "author": {
        "name": "Guillaume Nodet",
        "email": "gnodet@gmail.com",
        "time": "Sun Jun 07 07:04:18 2026 +0000"
      },
      "committer": {
        "name": "Guillaume Nodet",
        "email": "gnodet@gmail.com",
        "time": "Tue Jun 16 12:10:25 2026 +0200"
      },
      "message": "Fix WagonTransporter pollWagon — release wagon on reconnect failure instead of re-queuing\n"
    },
    {
      "commit": "42339126041d3050407648587f12557009093c70",
      "tree": "0d09e9d34281fe051c56d060b6a72a9d04fcc7fb",
      "parents": [
        "84e73e14bd5ae0b7360f98a66858ed3983ad0c1d"
      ],
      "author": {
        "name": "Guillaume Nodet",
        "email": "gnodet@gmail.com",
        "time": "Sun Jun 07 07:00:53 2026 +0000"
      },
      "committer": {
        "name": "Guillaume Nodet",
        "email": "gnodet@gmail.com",
        "time": "Tue Jun 16 12:10:25 2026 +0200"
      },
      "message": "Fix CompositeNamedLock — remove redundant double unlockAll\n\nF-31: Return false immediately after unlockAll() on lock failure\ninstead of breaking out of the loop and calling unlockAll() again\non the already-empty deque.\n\n"
    },
    {
      "commit": "84e73e14bd5ae0b7360f98a66858ed3983ad0c1d",
      "tree": "8d5e90a21820f9a10b3618e39e36701095d0ffcc",
      "parents": [
        "25685cfc0e935fbedb96e672ba2888c8d18cab73"
      ],
      "author": {
        "name": "Guillaume Nodet",
        "email": "gnodet@gmail.com",
        "time": "Sun Jun 07 06:59:16 2026 +0000"
      },
      "committer": {
        "name": "Guillaume Nodet",
        "email": "gnodet@gmail.com",
        "time": "Tue Jun 16 12:10:25 2026 +0200"
      },
      "message": "Fix lazy hashCode fields — add volatile in 4 classes\n\nF-29: Make cached hashCode fields volatile in ExclusionDependencySelector,\nAndDependencySelector, AndDependencyTraverser, and ChainedVersionFilter\nto ensure visibility across threads.\n\n"
    },
    {
      "commit": "25685cfc0e935fbedb96e672ba2888c8d18cab73",
      "tree": "4fb4892050342a8ed59a0bd688e13673038ca1e9",
      "parents": [
        "e768943d0f25bca56d1c8811d6ca0d37808c24e6"
      ],
      "author": {
        "name": "Guillaume Nodet",
        "email": "gnodet@gmail.com",
        "time": "Sun Jun 07 06:54:07 2026 +0000"
      },
      "committer": {
        "name": "Guillaume Nodet",
        "email": "gnodet@gmail.com",
        "time": "Tue Jun 16 12:10:25 2026 +0200"
      },
      "message": "Fix TransferResource field visibility — add volatile\n\nF-27: Make contentLength and resumeOffset volatile to ensure\nvisibility when written on worker threads and read by monitoring\nor logging threads.\n\n"
    },
    {
      "commit": "e768943d0f25bca56d1c8811d6ca0d37808c24e6",
      "tree": "04446c7a0b55821aaad1251c9c9b9464b05fc0fc",
      "parents": [
        "8876c4ec9cb7bed8fa86fd047bb1dc5cad0fbfa8"
      ],
      "author": {
        "name": "Guillaume Nodet",
        "email": "gnodet@gmail.com",
        "time": "Sun Jun 07 06:53:27 2026 +0000"
      },
      "committer": {
        "name": "Guillaume Nodet",
        "email": "gnodet@gmail.com",
        "time": "Tue Jun 16 12:10:25 2026 +0200"
      },
      "message": "Fix BasicRepositoryConnectorFactory.priority — add volatile\n\nF-26: Make the priority field volatile to ensure cross-thread\nvisibility between setPriority() and getPriority() calls.\n\n"
    },
    {
      "commit": "8876c4ec9cb7bed8fa86fd047bb1dc5cad0fbfa8",
      "tree": "80a23c9ac6d53b7125a56a39c11d2ed7a93aeee0",
      "parents": [
        "3ee57067c0ea8d17cf44517b772a89610f493e9a"
      ],
      "author": {
        "name": "Guillaume Nodet",
        "email": "gnodet@gmail.com",
        "time": "Sun Jun 07 06:52:41 2026 +0000"
      },
      "committer": {
        "name": "Guillaume Nodet",
        "email": "gnodet@gmail.com",
        "time": "Tue Jun 16 12:10:25 2026 +0200"
      },
      "message": "Fix Results.errorPath visibility — add volatile\n\nF-25: Make errorPath volatile to ensure cross-thread visibility\nwhen set from parallel stream workers and read from the main thread.\n\n"
    },
    {
      "commit": "3ee57067c0ea8d17cf44517b772a89610f493e9a",
      "tree": "11d70ecb4bb928263bae26cd6ba0f6ff2dc4f5c6",
      "parents": [
        "a96473d4e909ff7fb135f37cd529c9711be63f54"
      ],
      "author": {
        "name": "Guillaume Nodet",
        "email": "gnodet@gmail.com",
        "time": "Sun Jun 07 06:51:31 2026 +0000"
      },
      "committer": {
        "name": "Guillaume Nodet",
        "email": "gnodet@gmail.com",
        "time": "Tue Jun 16 12:10:25 2026 +0200"
      },
      "message": "Fix GenericVersionScheme racy cache statistics\n\nF-24: Use a single computeIfAbsent() call instead of separate\nget() then computeIfAbsent(), and derive hit/miss statistics\nfrom whether the mapping function was invoked.\n\n"
    },
    {
      "commit": "a96473d4e909ff7fb135f37cd529c9711be63f54",
      "tree": "8503d38e140825218534927f218a61e96bbd5cf7",
      "parents": [
        "436cf8b016552f8a8e930f41704e01a7b76260e7"
      ],
      "author": {
        "name": "Guillaume Nodet",
        "email": "gnodet@gmail.com",
        "time": "Sun Jun 07 06:50:27 2026 +0000"
      },
      "committer": {
        "name": "Guillaume Nodet",
        "email": "gnodet@gmail.com",
        "time": "Tue Jun 16 12:10:25 2026 +0200"
      },
      "message": "Fix Redisson trySetPermits() — log warning on failure\n\nF-22: Check the return value of trySetPermits(). If it returns false\n(e.g., a crashed process left the semaphore in a depleted state),\nlog a warning instead of silently proceeding with a potentially\nbroken semaphore.\n\n"
    },
    {
      "commit": "436cf8b016552f8a8e930f41704e01a7b76260e7",
      "tree": "f8c32cfcb8f07ba1708881182049af35772a8430",
      "parents": [
        "1c86ff471bf25a1b69fd47ce7d05aaace89f1c86"
      ],
      "author": {
        "name": "Guillaume Nodet",
        "email": "gnodet@gmail.com",
        "time": "Sun Jun 07 06:48:54 2026 +0000"
      },
      "committer": {
        "name": "Guillaume Nodet",
        "email": "gnodet@gmail.com",
        "time": "Tue Jun 16 12:10:25 2026 +0200"
      },
      "message": "Fix NamedLockFactorySupport getLock/shutdown race\n\nF-21: Re-check shutdown flag inside the locks.compute() lambda to\nprevent creating locks on a backend that was shut down between the\ninitial check and the actual lock creation.\n\n"
    },
    {
      "commit": "1c86ff471bf25a1b69fd47ce7d05aaace89f1c86",
      "tree": "2f964f200d35600b9a8255aa7e4ed0dd824809e4",
      "parents": [
        "99147f8789855ce2aa14f855f5d032522cce26e4"
      ],
      "author": {
        "name": "Guillaume Nodet",
        "email": "gnodet@gmail.com",
        "time": "Sun Jun 07 06:47:49 2026 +0000"
      },
      "committer": {
        "name": "Guillaume Nodet",
        "email": "gnodet@gmail.com",
        "time": "Tue Jun 16 12:10:25 2026 +0200"
      },
      "message": "Fix IpcServer Lock.unlock() — complete futures outside monitor\n\nF-20: Collect futures to complete during the synchronized block but\ncomplete them after releasing the Lock monitor, preventing I/O\noperations (socket writes in thenRun callbacks) from being\nserialized under the lock.\n\n"
    },
    {
      "commit": "99147f8789855ce2aa14f855f5d032522cce26e4",
      "tree": "a19ef9269b57f3a3fa9a8bd89840208ae23d04cd",
      "parents": [
        "ee8c2b00951105d24259c9de2179d3a69eb97c23"
      ],
      "author": {
        "name": "Guillaume Nodet",
        "email": "gnodet@gmail.com",
        "time": "Sun Jun 07 06:46:34 2026 +0000"
      },
      "committer": {
        "name": "Guillaume Nodet",
        "email": "gnodet@gmail.com",
        "time": "Tue Jun 16 12:10:25 2026 +0200"
      },
      "message": "Fix IpcServer Lock memory leak — remove empty locks from map\n\nF-19: Remove Lock entries from the locks ConcurrentHashMap when\nholders and waiters are both empty after unlock, preventing\nunbounded accumulation over the server\u0027s lifetime.\n\n"
    },
    {
      "commit": "ee8c2b00951105d24259c9de2179d3a69eb97c23",
      "tree": "47fac490e5ffc64a7ce7f6e99c14a5e6286e3699",
      "parents": [
        "b2b84d66cc18dc737ad8985a8cec37796d7cc1dc"
      ],
      "author": {
        "name": "Guillaume Nodet",
        "email": "gnodet@gmail.com",
        "time": "Sun Jun 07 06:45:07 2026 +0000"
      },
      "committer": {
        "name": "Guillaume Nodet",
        "email": "gnodet@gmail.com",
        "time": "Tue Jun 16 12:10:25 2026 +0200"
      },
      "message": "Fix IpcServer.expirationCheck() crash on negative sleep argument\n\nF-18: Clamp Thread.sleep() argument to minimum 1ms to prevent\nIllegalArgumentException when left goes negative while clients\nare still connected. Previously this silently killed the expiration\nthread, causing the server to never shut down.\n\n"
    },
    {
      "commit": "b2b84d66cc18dc737ad8985a8cec37796d7cc1dc",
      "tree": "697bd2f18d0ca9e6614e47392515f740d9732df2",
      "parents": [
        "0a138b386053560121a48873b6004d4339f9cb02"
      ],
      "author": {
        "name": "Guillaume Nodet",
        "email": "gnodet@gmail.com",
        "time": "Sun Jun 07 06:43:49 2026 +0000"
      },
      "committer": {
        "name": "Guillaume Nodet",
        "email": "gnodet@gmail.com",
        "time": "Tue Jun 16 12:10:25 2026 +0200"
      },
      "message": "Fix CachingArtifactTypeRegistry — use ConcurrentHashMap\n\nF-17: Replace plain HashMap with ConcurrentHashMap to prevent\ncorruption when concurrent parallel stream workers query the\nartifact type registry simultaneously.\n\n"
    },
    {
      "commit": "0a138b386053560121a48873b6004d4339f9cb02",
      "tree": "a30860a13fb97b4402f2065dc9b9bc5eb4f6fb63",
      "parents": [
        "4f9e372021c8dcab1921bf4977ece6f2dcc98720"
      ],
      "author": {
        "name": "Guillaume Nodet",
        "email": "gnodet@gmail.com",
        "time": "Sun Jun 07 06:42:12 2026 +0000"
      },
      "committer": {
        "name": "Guillaume Nodet",
        "email": "gnodet@gmail.com",
        "time": "Tue Jun 16 12:10:25 2026 +0200"
      },
      "message": "Fix SimpleArtifactTypeRegistry — use ConcurrentHashMap\n\nF-16: Replace plain HashMap with ConcurrentHashMap to ensure\nvisibility of types populated on the main thread to worker threads\nquerying via the session.\n\n"
    },
    {
      "commit": "4f9e372021c8dcab1921bf4977ece6f2dcc98720",
      "tree": "4a6a98e410d513e4f7b36c986cda27517218ecb6",
      "parents": [
        "47fb6945ca17b02b0a93c049f53181389f43fa10"
      ],
      "author": {
        "name": "Guillaume Nodet",
        "email": "gnodet@gmail.com",
        "time": "Sun Jun 07 06:41:28 2026 +0000"
      },
      "committer": {
        "name": "Guillaume Nodet",
        "email": "gnodet@gmail.com",
        "time": "Tue Jun 16 12:10:25 2026 +0200"
      },
      "message": "Fix DefaultAuthenticationSelector — use ConcurrentHashMap\n\nF-15: Replace plain HashMap with ConcurrentHashMap to prevent data\ncorruption when add() and getAuthentication() are called from\ndifferent threads.\n\n"
    },
    {
      "commit": "47fb6945ca17b02b0a93c049f53181389f43fa10",
      "tree": "02db379a8fc3d053c4e54a8352aa395a831eebfb",
      "parents": [
        "3c9ee81d017601fde10a759fc273b015fe8c09a6"
      ],
      "author": {
        "name": "Guillaume Nodet",
        "email": "gnodet@gmail.com",
        "time": "Sun Jun 07 06:40:38 2026 +0000"
      },
      "committer": {
        "name": "Guillaume Nodet",
        "email": "gnodet@gmail.com",
        "time": "Tue Jun 16 12:10:25 2026 +0200"
      },
      "message": "Fix DefaultMirrorSelector — use CopyOnWriteArrayList for mirrors\n\nF-14: Replace plain ArrayList with CopyOnWriteArrayList to prevent\nConcurrentModificationException when add() is called concurrently\nwith getMirror()/findMirror() iteration.\n\n"
    },
    {
      "commit": "3c9ee81d017601fde10a759fc273b015fe8c09a6",
      "tree": "0c5fa5fc901c271d3c0a6d699b8841537992bc95",
      "parents": [
        "086d05bbd933f50a7026817132045f63c7538e36"
      ],
      "author": {
        "name": "Guillaume Nodet",
        "email": "gnodet@gmail.com",
        "time": "Sun Jun 07 06:39:39 2026 +0000"
      },
      "committer": {
        "name": "Guillaume Nodet",
        "email": "gnodet@gmail.com",
        "time": "Tue Jun 16 12:10:25 2026 +0200"
      },
      "message": "Fix DefaultProxySelector — use CopyOnWriteArrayList for proxies\n\nF-13: Replace plain ArrayList with CopyOnWriteArrayList to prevent\nConcurrentModificationException when add() is called concurrently\nwith getProxy() iteration.\n\n"
    },
    {
      "commit": "086d05bbd933f50a7026817132045f63c7538e36",
      "tree": "e81196e336fca466bc9aa12be52ffad35514ebf2",
      "parents": [
        "3785bf51153b74cf685d800f543a625086ff8d6d"
      ],
      "author": {
        "name": "Guillaume Nodet",
        "email": "gnodet@gmail.com",
        "time": "Sun Jun 07 06:37:36 2026 +0000"
      },
      "committer": {
        "name": "Guillaume Nodet",
        "email": "gnodet@gmail.com",
        "time": "Tue Jun 16 12:10:25 2026 +0200"
      },
      "message": "Fix WagonTransporter close-while-executing wagon leak\n\nF-12: After transfer completes, check if the transporter was closed\nduring execution. If so, disconnect and release the wagon instead of\nreturning it to the queue where it would never be cleaned up.\n\n"
    },
    {
      "commit": "3785bf51153b74cf685d800f543a625086ff8d6d",
      "tree": "e2edd5d247cb986f2f9855e93096463e42b6bec9",
      "parents": [
        "9c1182d7fc96178e0008c28c68fa30068c712291"
      ],
      "author": {
        "name": "Guillaume Nodet",
        "email": "gnodet@gmail.com",
        "time": "Sun Jun 07 06:36:14 2026 +0000"
      },
      "committer": {
        "name": "Guillaume Nodet",
        "email": "gnodet@gmail.com",
        "time": "Tue Jun 16 12:10:25 2026 +0200"
      },
      "message": "Fix DeferredCredentialsProvider — extend synchronized block\n\nF-11: Move delegate.getCredentials() inside the synchronized(factories)\nblock to prevent concurrent read/write on the underlying HashMap-backed\nBasicCredentialsProvider.\n\n"
    },
    {
      "commit": "9c1182d7fc96178e0008c28c68fa30068c712291",
      "tree": "6a3055a679e0661a23ee6be8ee7321934b82f53e",
      "parents": [
        "80e49a7a64e0272ee0c153de366e6767d1951bde"
      ],
      "author": {
        "name": "Guillaume Nodet",
        "email": "gnodet@gmail.com",
        "time": "Sun Jun 07 06:34:47 2026 +0000"
      },
      "committer": {
        "name": "Guillaume Nodet",
        "email": "gnodet@gmail.com",
        "time": "Tue Jun 16 12:10:25 2026 +0200"
      },
      "message": "Fix Results.addException/addCycle thread safety for parallelStream\n\nF-10: Synchronize addException() and addCycle() in Results to prevent\ndata races when called concurrently from BfDependencyCollector\u0027s\nparallelStream during version range resolution.\n\n"
    },
    {
      "commit": "80e49a7a64e0272ee0c153de366e6767d1951bde",
      "tree": "b02e11323d99ceccebe79447a0e2a3e1c40aaf55",
      "parents": [
        "329c4f242aa1c6a8be1b64b0edb28c550ba3346f"
      ],
      "author": {
        "name": "Guillaume Nodet",
        "email": "gnodet@gmail.com",
        "time": "Sun Jun 07 06:33:16 2026 +0000"
      },
      "committer": {
        "name": "Guillaume Nodet",
        "email": "gnodet@gmail.com",
        "time": "Tue Jun 16 12:10:25 2026 +0200"
      },
      "message": "Fix WeakInternPool.intern() non-atomic check-then-act\n\nF-09: Use map.compute() instead of separate get/put to make the\ninterning operation atomic, preventing duplicate objects from\ndefeating heap deduplication during concurrent descriptor resolution.\n\n"
    },
    {
      "commit": "329c4f242aa1c6a8be1b64b0edb28c550ba3346f",
      "tree": "1346483ba7049645da2b4dc288765b6e873806b3",
      "parents": [
        "9341e597db38d5a91906457ddfb52507c6cb3974"
      ],
      "author": {
        "name": "Guillaume Nodet",
        "email": "gnodet@gmail.com",
        "time": "Sun Jun 07 06:31:50 2026 +0000"
      },
      "committer": {
        "name": "Guillaume Nodet",
        "email": "gnodet@gmail.com",
        "time": "Tue Jun 16 12:10:25 2026 +0200"
      },
      "message": "Fix DataPool cache initialization race — use computeIfAbsent\n\nF-08: Replace get-then-put pattern with cache.computeIfAbsent() for\nall four intern pools, preventing concurrent DataPool constructors\nfrom creating and using detached pool instances.\n\n"
    },
    {
      "commit": "9341e597db38d5a91906457ddfb52507c6cb3974",
      "tree": "e3c16e32d31d5cc35b8c40bf15bda2a0fdf72f87",
      "parents": [
        "7f10ebd22a0445b70f427a3e0c11b06b97a75c6c"
      ],
      "author": {
        "name": "Guillaume Nodet",
        "email": "gnodet@gmail.com",
        "time": "Sun Jun 07 06:30:12 2026 +0000"
      },
      "committer": {
        "name": "Guillaume Nodet",
        "email": "gnodet@gmail.com",
        "time": "Tue Jun 16 12:10:25 2026 +0200"
      },
      "message": "Fix SmartExecutor RejectedExecutionException causing await() hang\n\nF-07: When executor.submit() throws RejectedExecutionException, fall\nback to running the task on the caller thread. This prevents\nRunnableErrorForwarder.await() from hanging forever when the counter\nwas incremented by wrap() but the task never runs.\n\n"
    },
    {
      "commit": "7f10ebd22a0445b70f427a3e0c11b06b97a75c6c",
      "tree": "32f639be5da627d80617f92aaa1a041fc9f9364d",
      "parents": [
        "b241f2a022f17c59ed3e817cf21bcf267ccd46d1"
      ],
      "author": {
        "name": "Guillaume Nodet",
        "email": "gnodet@gmail.com",
        "time": "Sun Jun 07 06:28:39 2026 +0000"
      },
      "committer": {
        "name": "Guillaume Nodet",
        "email": "gnodet@gmail.com",
        "time": "Tue Jun 16 12:10:25 2026 +0200"
      },
      "message": "Fix Apache BasicAuthCache thread safety — use ConcurrentHashMap-backed AuthCache\n\nF-06: Replace BasicAuthCache (backed by plain HashMap) with a\nConcurrentAuthCache backed by ConcurrentHashMap, preventing data\ncorruption when concurrent requests call authCache.put() during\npreemptive auth.\n\n"
    },
    {
      "commit": "b241f2a022f17c59ed3e817cf21bcf267ccd46d1",
      "tree": "f1e57a2b1e79883f9c5d6682286f63c0735de6f3",
      "parents": [
        "adb0e8eb653a8cc71499b730840f6ad2aa6ed71d"
      ],
      "author": {
        "name": "Guillaume Nodet",
        "email": "gnodet@gmail.com",
        "time": "Sun Jun 07 06:21:48 2026 +0000"
      },
      "committer": {
        "name": "Guillaume Nodet",
        "email": "gnodet@gmail.com",
        "time": "Tue Jun 16 12:10:25 2026 +0200"
      },
      "message": "Fix IpcServer clients HashMap — use ConcurrentHashMap\n\nF-03: Replace plain HashMap with ConcurrentHashMap for the clients\nmap so that close() and expirationCheck() can safely access it\nwithout synchronization, preventing ConcurrentModificationException\nand data races.\n\n"
    },
    {
      "commit": "adb0e8eb653a8cc71499b730840f6ad2aa6ed71d",
      "tree": "443f1f08a68aac0acbd440238e44eef1817e9481",
      "parents": [
        "1635bce54af20a0272d1b985ade856bc8223b9fa"
      ],
      "author": {
        "name": "Guillaume Nodet",
        "email": "gnodet@gmail.com",
        "time": "Sun Jun 07 06:20:03 2026 +0000"
      },
      "committer": {
        "name": "Guillaume Nodet",
        "email": "gnodet@gmail.com",
        "time": "Tue Jun 16 12:10:25 2026 +0200"
      },
      "message": "Fix IpcClient field visibility — make socket/output/input volatile\n\nF-02: Declare socket, output, input, and receiver fields as volatile\nso that writes in close(Throwable) are visible to concurrent readers\nin send() and receive() without requiring synchronization on this.\n\n"
    },
    {
      "commit": "1635bce54af20a0272d1b985ade856bc8223b9fa",
      "tree": "676cc2bf16e07aa68295035c156dca599070fd7d",
      "parents": [
        "73949d445ffd28c785529a92569deb6b26932ab9"
      ],
      "author": {
        "name": "dependabot[bot]",
        "email": "49699333+dependabot[bot]@users.noreply.github.com",
        "time": "Tue Jun 16 09:54:08 2026 +0200"
      },
      "committer": {
        "name": "GitHub",
        "email": "noreply@github.com",
        "time": "Tue Jun 16 09:54:08 2026 +0200"
      },
      "message": "Bump org.redisson:redisson from 4.5.0 to 4.6.0 (#1927)\n\nBumps [org.redisson:redisson](https://github.com/redisson/redisson) from 4.5.0 to 4.6.0.\n- [Release notes](https://github.com/redisson/redisson/releases)\n- [Changelog](https://github.com/redisson/redisson/blob/master/CHANGELOG.md)\n- [Commits](https://github.com/redisson/redisson/compare/redisson-4.5.0...redisson-4.6.0)\n\n---\nupdated-dependencies:\n- dependency-name: org.redisson:redisson\n  dependency-version: 4.6.0\n  dependency-type: direct:production\n  update-type: version-update:semver-minor\n...\n\nSigned-off-by: dependabot[bot] \u003csupport@github.com\u003e\nCo-authored-by: dependabot[bot] \u003c49699333+dependabot[bot]@users.noreply.github.com\u003e"
    },
    {
      "commit": "73949d445ffd28c785529a92569deb6b26932ab9",
      "tree": "e2fc0600af181885fe1dbd6fd2177c19888317b8",
      "parents": [
        "f4dbdd9c6cd9749b6ecb35ea6c7f9cf4ffe69928"
      ],
      "author": {
        "name": "Tamas Cservenak",
        "email": "tamas@cservenak.net",
        "time": "Mon Jun 15 20:52:03 2026 +0200"
      },
      "committer": {
        "name": "GitHub",
        "email": "noreply@github.com",
        "time": "Mon Jun 15 20:52:03 2026 +0200"
      },
      "message": "Javadoc update (#1925)\n\nUpdate Javadoc of policies, precisely explaining which policy what\nexpects or enforces.\n\nFixes #1920"
    },
    {
      "commit": "f4dbdd9c6cd9749b6ecb35ea6c7f9cf4ffe69928",
      "tree": "a4f90f5369dcff675b4013e52241a9fd6ae1b86d",
      "parents": [
        "70566e835090a9f26c01f5531605f28bd484d994"
      ],
      "author": {
        "name": "Tamas Cservenak",
        "email": "tamas@cservenak.net",
        "time": "Mon Jun 15 15:39:46 2026 +0200"
      },
      "committer": {
        "name": "GitHub",
        "email": "noreply@github.com",
        "time": "Mon Jun 15 15:39:46 2026 +0200"
      },
      "message": "Fix ApacheTransport auth cache CCEx (#1923)\n\nStarted as proposed, to make session-wide auth cache string key classloader aware. Then realized, we have \"classloader aware\" class, that we make into string, with tricks, to make it \"classloader aware\", and this sounds awkward. Hence, Keys helper class.\n\nThis PR also revealed a bug, hidden deep, where (probably a copy pasted) code snippet used wrong key, see `RemoteRepositoryFilterSourceSupport`.\n\nHelper allows three key \"flavors\" (global/string-only, ClassLoader-aware/Class-element, private/Object-identity), and it can be used based on required use case."
    },
    {
      "commit": "70566e835090a9f26c01f5531605f28bd484d994",
      "tree": "898e4c2a8ef5ff210b2e729b6f38a3aadb7d6733",
      "parents": [
        "caf6d498f4cf7461530493d691d9b631c8ea6026"
      ],
      "author": {
        "name": "dependabot[bot]",
        "email": "49699333+dependabot[bot]@users.noreply.github.com",
        "time": "Mon Jun 15 05:23:14 2026 +0000"
      },
      "committer": {
        "name": "Sylwester Lachiewicz",
        "email": "slachiewicz@apache.org",
        "time": "Mon Jun 15 06:41:38 2026 -0400"
      },
      "message": "Bump io.minio:minio from 9.0.2 to 9.0.3\n\nBumps [io.minio:minio](https://github.com/minio/minio-java) from 9.0.2 to 9.0.3.\n- [Release notes](https://github.com/minio/minio-java/releases)\n- [Commits](https://github.com/minio/minio-java/compare/9.0.2...9.0.3)\n\n---\nupdated-dependencies:\n- dependency-name: io.minio:minio\n  dependency-version: 9.0.3\n  dependency-type: direct:production\n  update-type: version-update:semver-patch\n...\n\nSigned-off-by: dependabot[bot] \u003csupport@github.com\u003e"
    },
    {
      "commit": "caf6d498f4cf7461530493d691d9b631c8ea6026",
      "tree": "0cb4a26f4224a54663c4af23bd9a87b63f2ecdd3",
      "parents": [
        "e3d4ed55fe19ffaa0463c111484eda4740478e0a"
      ],
      "author": {
        "name": "Gerd Aschemann",
        "email": "github@aschemann.net",
        "time": "Sun Jun 14 14:57:38 2026 +0200"
      },
      "committer": {
        "name": "GitHub",
        "email": "noreply@github.com",
        "time": "Sun Jun 14 14:57:38 2026 +0200"
      },
      "message": "WarnChecksumPolicy: proceed on no checksums (#1922)\n\nOverride AbstractChecksumPolicy.onNoMoreChecksums() in\nWarnChecksumPolicy to log a warning and return instead of\ninheriting the unconditional throw. Brings the policy in\nline with its name: warn on issues but proceed.\n\nFailChecksumPolicy unchanged.\n\nRefs GH-1920."
    },
    {
      "commit": "e3d4ed55fe19ffaa0463c111484eda4740478e0a",
      "tree": "8db250b9e0d87534893b68dc44d050c664ee3044",
      "parents": [
        "399e68fee60c7fd3ad21a3cb28a3615e720cfcec"
      ],
      "author": {
        "name": "Tamas Cservenak",
        "email": "tamas@cservenak.net",
        "time": "Sun Jun 14 11:10:31 2026 +0200"
      },
      "committer": {
        "name": "GitHub",
        "email": "noreply@github.com",
        "time": "Sun Jun 14 11:10:31 2026 +0200"
      },
      "message": "Fix for ChainedWorkspaceReader (#1909)\n\nThe reader instances once set, are immutable, but repository instances returned by readers may change (their key)."
    },
    {
      "commit": "399e68fee60c7fd3ad21a3cb28a3615e720cfcec",
      "tree": "abe314e84fdd700608c9b72ccc3580390f32019c",
      "parents": [
        "3dcd686638ddee706cedf517b172da7511712db1"
      ],
      "author": {
        "name": "Tamas Cservenak",
        "email": "tamas@cservenak.net",
        "time": "Sat Jun 13 21:43:35 2026 +0200"
      },
      "committer": {
        "name": "GitHub",
        "email": "noreply@github.com",
        "time": "Sat Jun 13 21:43:35 2026 +0200"
      },
      "message": "Checksums: lack of information (#1917)\n\nIssue: `TrustedChecksumsArtifactResolverPostProcessor` uses wrong ctor of `ChecksumFailureExxeption` and thus, created exceptions with lack of information. This was easy mistake to do, as exception already had way too many constructors.\n\nFix: This exception is quite special, as it covers many cases: real mismatch, processing issues during checksum calculation and lack of checksums. The Resolver intent is to always provide as much information as possible. Hence, deprecated all constructors, not using them in production code, instead using new provided helper methods for 3 cases (mismatch, lack of and processing error), making sure that in each case we provide as much information as possible."
    },
    {
      "commit": "3dcd686638ddee706cedf517b172da7511712db1",
      "tree": "135e5f5b408b943f06958a159e0254347814ddfa",
      "parents": [
        "155bf5ae08678a739602dc788dc518277a31ade0"
      ],
      "author": {
        "name": "dependabot[bot]",
        "email": "49699333+dependabot[bot]@users.noreply.github.com",
        "time": "Fri Jun 12 14:27:34 2026 +0200"
      },
      "committer": {
        "name": "GitHub",
        "email": "noreply@github.com",
        "time": "Fri Jun 12 14:27:34 2026 +0200"
      },
      "message": "Bump dev.sigstore:sigstore-java from 2.1.0 to 2.2.0 (#1918)\n\nBumps [dev.sigstore:sigstore-java](https://github.com/sigstore/sigstore-java) from 2.1.0 to 2.2.0.\n- [Release notes](https://github.com/sigstore/sigstore-java/releases)\n- [Changelog](https://github.com/sigstore/sigstore-java/blob/main/CHANGELOG.md)\n- [Commits](https://github.com/sigstore/sigstore-java/compare/v2.1.0...v2.2.0)\n\n---\nupdated-dependencies:\n- dependency-name: dev.sigstore:sigstore-java\n  dependency-version: 2.2.0\n  dependency-type: direct:production\n  update-type: version-update:semver-minor\n...\n\nSigned-off-by: dependabot[bot] \u003csupport@github.com\u003e\nCo-authored-by: dependabot[bot] \u003c49699333+dependabot[bot]@users.noreply.github.com\u003e"
    },
    {
      "commit": "155bf5ae08678a739602dc788dc518277a31ade0",
      "tree": "5d8f3d789089e4e68299510ff558f492db3d796a",
      "parents": [
        "702d754ec41c9cbbe1c5ec5befe9ffa3df395397"
      ],
      "author": {
        "name": "dependabot[bot]",
        "email": "49699333+dependabot[bot]@users.noreply.github.com",
        "time": "Wed Jun 10 14:15:56 2026 +0200"
      },
      "committer": {
        "name": "GitHub",
        "email": "noreply@github.com",
        "time": "Wed Jun 10 14:15:56 2026 +0200"
      },
      "message": "Bump io.minio:minio from 9.0.1 to 9.0.2 (#1916)\n\nBumps [io.minio:minio](https://github.com/minio/minio-java) from 9.0.1 to 9.0.2.\n- [Release notes](https://github.com/minio/minio-java/releases)\n- [Commits](https://github.com/minio/minio-java/compare/9.0.1...9.0.2)\n\n---\nupdated-dependencies:\n- dependency-name: io.minio:minio\n  dependency-version: 9.0.2\n  dependency-type: direct:production\n  update-type: version-update:semver-patch\n...\n\nSigned-off-by: dependabot[bot] \u003csupport@github.com\u003e\nCo-authored-by: dependabot[bot] \u003c49699333+dependabot[bot]@users.noreply.github.com\u003e"
    },
    {
      "commit": "702d754ec41c9cbbe1c5ec5befe9ffa3df395397",
      "tree": "e075f1427ddfac1e01584bcb4039a2d1387bca14",
      "parents": [
        "b06e62f6e1020be7fa45eddcb5ee8249056ac14b"
      ],
      "author": {
        "name": "dependabot[bot]",
        "email": "49699333+dependabot[bot]@users.noreply.github.com",
        "time": "Tue Jun 09 21:14:42 2026 +0200"
      },
      "committer": {
        "name": "GitHub",
        "email": "noreply@github.com",
        "time": "Tue Jun 09 21:14:42 2026 +0200"
      },
      "message": "Bump okhttpVersion from 5.3.2 to 5.4.0 (#1914)\n\nBumps `okhttpVersion` from 5.3.2 to 5.4.0.\n\nUpdates `com.squareup.okhttp3:okhttp-bom` from 5.3.2 to 5.4.0\n- [Changelog](https://github.com/square/okhttp/blob/master/CHANGELOG.md)\n- [Commits](https://github.com/square/okhttp/compare/parent-5.3.2...parent-5.4.0)\n\nUpdates `com.squareup.okhttp3:okhttp-jvm` from 5.3.2 to 5.4.0\n- [Changelog](https://github.com/square/okhttp/blob/master/CHANGELOG.md)\n- [Commits](https://github.com/square/okhttp/compare/parent-5.3.2...parent-5.4.0)\n\n---\nupdated-dependencies:\n- dependency-name: com.squareup.okhttp3:okhttp-bom\n  dependency-version: 5.4.0\n  dependency-type: direct:production\n  update-type: version-update:semver-minor\n- dependency-name: com.squareup.okhttp3:okhttp-jvm\n  dependency-version: 5.4.0\n  dependency-type: direct:production\n  update-type: version-update:semver-minor\n...\n\nSigned-off-by: dependabot[bot] \u003csupport@github.com\u003e\nCo-authored-by: dependabot[bot] \u003c49699333+dependabot[bot]@users.noreply.github.com\u003e"
    },
    {
      "commit": "b06e62f6e1020be7fa45eddcb5ee8249056ac14b",
      "tree": "095c210c268425fb8f33d4683f5cb77172af6781",
      "parents": [
        "f31325afa4c3441b985916779535912fe73cb775"
      ],
      "author": {
        "name": "Guillaume Nodet",
        "email": "gnodet@gmail.com",
        "time": "Tue Jun 09 11:37:10 2026 +0200"
      },
      "committer": {
        "name": "GitHub",
        "email": "noreply@github.com",
        "time": "Tue Jun 09 11:37:10 2026 +0200"
      },
      "message": "Fix inverted SIGTSTP condition in IPC server (#1915)\n\nThe condition for ignoring SIGTSTP was inverted: it tried to\nignore TSTP on Windows (where it does not exist, causing a crash)\nand did nothing on Unix (where TSTP exists, causing the daemon\nto suspend on Ctrl-Z).\n\nFix: ignore SIGTSTP only on non-Windows (Unix) systems."
    },
    {
      "commit": "f31325afa4c3441b985916779535912fe73cb775",
      "tree": "f6298382fadddaff3b6465557081367474a5a910",
      "parents": [
        "9975d7825ca58baa70d4e1f01e4e9e294cffb2ff"
      ],
      "author": {
        "name": "Guillaume Nodet",
        "email": "gnodet@gmail.com",
        "time": "Mon Jun 08 20:17:39 2026 +0000"
      },
      "committer": {
        "name": "Guillaume Nodet",
        "email": "gnodet@gmail.com",
        "time": "Mon Jun 08 20:17:39 2026 +0000"
      },
      "message": "Disable IPC named lock ITs on Windows\n\nUnix domain sockets (AF_UNIX) used by the IPC named lock implementation\nare not reliably supported on Windows, causing intermittent deadlocks and\ntimeouts in CI. Disable the ITs on Windows until the implementation is\nfixed to handle Windows socket cleanup properly.\n"
    },
    {
      "commit": "9975d7825ca58baa70d4e1f01e4e9e294cffb2ff",
      "tree": "f45eff57ae5617c953821ba56c9a0df21c28e635",
      "parents": [
        "74605684d6ebd38251ca1791c8acd42ff8d6aa78"
      ],
      "author": {
        "name": "Guillaume Nodet",
        "email": "gnodet@gmail.com",
        "time": "Mon Jun 08 22:03:22 2026 +0200"
      },
      "committer": {
        "name": "GitHub",
        "email": "noreply@github.com",
        "time": "Mon Jun 08 22:03:22 2026 +0200"
      },
      "message": "Bug: fix IPC named lock client-side robustness for Windows (#1910)\n\n* Bug: fix IPC named lock client-side robustness for Windows\n\nWhen lock acquisition times out in IpcNamedLock, the cleanup call to\nclient.unlock() could either hang forever (Long.MAX_VALUE timeout) or\nthrow RuntimeException. On Windows, where IPC socket behavior can\ndiffer, this causes test threads to either block indefinitely or crash\nwithout signaling their CountDownLatch, making the test appear to hang.\n\nFour changes:\n\n1. IpcNamedLock: wrap cleanup unlock in try-catch (tryUnlock) so that a\n   failure during timeout handling returns false instead of crashing the\n   calling thread. This is the primary fix for the exclusiveAccess test\n   hang on Windows.\n\n2. IpcClient.unlock/stopServer: replace Long.MAX_VALUE timeouts with\n   bounded values (10s/30s) so operations fail fast when the server is\n   unresponsive.\n\n3. IpcClient.receive: complete the future exceptionally on empty\n   responses instead of throwing, which would kill the receiver thread\n   and break all subsequent operations on the shared client.\n\n4. IpcClient.close: properly call close() on EOF to clean up pending\n   futures, and reset the initialized flag to prevent stale state.\n\n* Bug: fix race condition in IpcClient.send() causing NPE on Windows\n\nThe send() method read the `output` field multiple times without holding\nthe same lock as close(Throwable), which nulls it under synchronized(this).\nBetween ensureInitialized() returning and reaching synchronized(output),\nthe receiver thread could close the connection and null out the field,\ncausing a NullPointerException at output.flush().\n\nFix by capturing the output field in a local variable immediately after\nensureInitialized(), checking for null, and using the local throughout\nthe synchronized block.\n\n* ci: retrigger Windows CI validation (run 3/3)"
    }
  ],
  "next": "74605684d6ebd38251ca1791c8acd42ff8d6aa78"
}
