)]}'
{
  "log": [
    {
      "commit": "cefbdb21eabb4afd56a7aa0a9d77ebcc55738fff",
      "tree": "90278160f7ac0bdd6e69ff47dc3f6d4b042c895c",
      "parents": [
        "e23e7d7262a226873132db13b41860d6403d48d3"
      ],
      "author": {
        "name": "Jacopo Cappellato",
        "email": "jacopo.cappellato@gmail.com",
        "time": "Mon Jul 27 18:40:43 2026 +0200"
      },
      "committer": {
        "name": "Jacopo Cappellato",
        "email": "jacopo.cappellato@gmail.com",
        "time": "Tue Jul 28 10:41:02 2026 +0200"
      },
      "message": "Fixed: Add validation for product image file names in renameImage to prevent path traversal\n"
    },
    {
      "commit": "e23e7d7262a226873132db13b41860d6403d48d3",
      "tree": "9f5865222a991ae4f818bf0d16740be3edcb6319",
      "parents": [
        "4bd9d1d2f0ae82ed8689ddccf7e8c3eb64df9c2e"
      ],
      "author": {
        "name": "dependabot[bot]",
        "email": "49699333+dependabot[bot]@users.noreply.github.com",
        "time": "Fri Jul 24 14:01:33 2026 +0000"
      },
      "committer": {
        "name": "Jacopo Cappellato",
        "email": "jacopo.cappellato@gmail.com",
        "time": "Mon Jul 27 11:54:13 2026 +0200"
      },
      "message": "Bump docker/login-action from 4.4.0 to 4.5.1\n\nBumps [docker/login-action](https://github.com/docker/login-action) from 4.4.0 to 4.5.1.\n- [Release notes](https://github.com/docker/login-action/releases)\n- [Commits](https://github.com/docker/login-action/compare/af1e73f918a031802d376d3c8bbc3fe56130a9b0...abd2ef45e78c5afb21d64d4ca52ee8550d9572c7)\n\n---\nupdated-dependencies:\n- dependency-name: docker/login-action\n  dependency-version: 4.5.1\n  dependency-type: direct:production\n  update-type: version-update:semver-minor\n...\n\nSigned-off-by: dependabot[bot] \u003csupport@github.com\u003e"
    },
    {
      "commit": "4bd9d1d2f0ae82ed8689ddccf7e8c3eb64df9c2e",
      "tree": "48782d411c87fe4a67f7ffb78418749de5c8e8c4",
      "parents": [
        "0877621dc28dd89527e7b5e6f0ce5e379b037b84"
      ],
      "author": {
        "name": "Jacopo Cappellato",
        "email": "jacopo.cappellato@gmail.com",
        "time": "Mon Jul 27 10:26:47 2026 +0200"
      },
      "committer": {
        "name": "Jacopo Cappellato",
        "email": "jacopo.cappellato@gmail.com",
        "time": "Mon Jul 27 11:01:35 2026 +0200"
      },
      "message": "Bump brace-expansion to 5.0.8 and minimatch to 10.2.5\n"
    },
    {
      "commit": "0877621dc28dd89527e7b5e6f0ce5e379b037b84",
      "tree": "0ba626c2e582436bb20d1750c8acd94ff2468d80",
      "parents": [
        "7eecacc90dab86f7a109059ff43d0d06d8171165"
      ],
      "author": {
        "name": "dependabot[bot]",
        "email": "49699333+dependabot[bot]@users.noreply.github.com",
        "time": "Fri Jul 24 14:01:43 2026 +0000"
      },
      "committer": {
        "name": "Jacopo Cappellato",
        "email": "jacopo.cappellato@gmail.com",
        "time": "Sat Jul 25 09:13:55 2026 +0200"
      },
      "message": "Bump ossf/scorecard-action from 2.4.3 to 2.4.4\n\nBumps [ossf/scorecard-action](https://github.com/ossf/scorecard-action) from 2.4.3 to 2.4.4.\n- [Release notes](https://github.com/ossf/scorecard-action/releases)\n- [Changelog](https://github.com/ossf/scorecard-action/blob/main/RELEASE.md)\n- [Commits](https://github.com/ossf/scorecard-action/compare/4eaacf0543bb3f2c246792bd56e8cdeffafb205a...2d1146689b8cda280b9bc96326124645441f03bc)\n\n---\nupdated-dependencies:\n- dependency-name: ossf/scorecard-action\n  dependency-version: 2.4.4\n  dependency-type: direct:production\n  update-type: version-update:semver-patch\n...\n\nSigned-off-by: dependabot[bot] \u003csupport@github.com\u003e"
    },
    {
      "commit": "7eecacc90dab86f7a109059ff43d0d06d8171165",
      "tree": "29b504ef3bfc87e4fd024201e486f19168d52491",
      "parents": [
        "cff2b47bb22effc2dea8963e4d67eb76c2b18664"
      ],
      "author": {
        "name": "diveshdut",
        "email": "divesh.dutta@hotwax.co",
        "time": "Wed Jul 22 11:58:03 2026 +0530"
      },
      "committer": {
        "name": "Divesh Dutta",
        "email": "124163540+diveshdut@users.noreply.github.com",
        "time": "Fri Jul 24 21:26:14 2026 +0530"
      },
      "message": "OFBIZ-13460: Fix checkstyle formatting for MRP run log changes\n"
    },
    {
      "commit": "cff2b47bb22effc2dea8963e4d67eb76c2b18664",
      "tree": "4377783881abd1644a477f12730f8ea6863bd58d",
      "parents": [
        "b81233fc6c5e09c14768e3b9b64ea1f26728ec04"
      ],
      "author": {
        "name": "diveshdut",
        "email": "divesh.dutta@hotwax.co",
        "time": "Fri Jul 24 21:02:39 2026 +0530"
      },
      "committer": {
        "name": "Divesh Dutta",
        "email": "124163540+diveshdut@users.noreply.github.com",
        "time": "Fri Jul 24 21:26:14 2026 +0530"
      },
      "message": "OFBIZ-13460: Add durable MRP run history and provenance\n"
    },
    {
      "commit": "b81233fc6c5e09c14768e3b9b64ea1f26728ec04",
      "tree": "4e293f6c13b3a38bf6992784965cb615c89b067b",
      "parents": [
        "b989dac76eb339f51d4237b451d6249cd27dc207"
      ],
      "author": {
        "name": "Divesh Dutta",
        "email": "124163540+diveshdut@users.noreply.github.com",
        "time": "Fri Jul 24 20:36:45 2026 +0530"
      },
      "committer": {
        "name": "GitHub",
        "email": "noreply@github.com",
        "time": "Fri Jul 24 20:36:45 2026 +0530"
      },
      "message": "OFBIZ-13461 : Avoid async RequirementStatus FK race after createRequirement (#1480)\n\n## Jira ticket:\n\nhttps://issues.apache.org/jira/browse/OFBIZ-13461\n\n## Summary\n\nThis fixes a timing-dependent foreign-key failure during requirement\nstatus creation.\n\nWhen `createRequirement` runs inside a larger transaction, its async\nSECA can invoke `createRequirementStatus` before the enclosing\ntransaction has fully committed. In that window, the new `Requirement`\nrow is not yet visible, and the `RequirementStatus` insert can fail\nwith:\n\n`REQ_STTS_REQ: OFBIZ.REQUIREMENT_STATUS FOREIGN KEY(REQUIREMENT_ID)\nREFERENCES OFBIZ.REQUIREMENT(REQUIREMENT_ID)`\n\nThis was observed from the Manufacturing `Run MRP` flow, but the\nunderlying bug is in the order-side requirement status SECA behavior.\n\n## Root Cause\n\nThe existing `createRequirement` SECA used `event\u003d\"commit\"` with\n`mode\u003d\"async\"`.\n\nThat is not a safe boundary when `createRequirement` participates in an\nouter transaction. The async follow-up may run before the outer\ntransaction is committed and globally visible.\n\nThis is a race condition rather than a deterministic logic error.\n\n## Changes\n\n- changed the `createRequirement` status SECA to\n`global-commit-post-run`\n- changed the `updateRequirement` status SECA to `global-commit`\n- added a focused order-side regression test for the outer-transaction\nscenario\n- registered the regression test in the order test suite\n\n## Why `global-commit-post-run`\n\n`createRequirementStatus` needs the generated `requirementId`.\n\n`global-commit-post-run` ensures:\n- the enclosing transaction has committed\n- the generated service output is still available to the follow-up async\naction\n\n## Tests\n\nAdded a focused regression test for the outer-transaction timing case:\n\n-\n`RequirementStatusEcaTests.testCreateRequirementStatusAfterOuterTransactionCommit`\n\nThis verifies that:\n\n- `createRequirement` can run inside an outer transaction\n- `RequirementStatus` is not created before commit\n- `RequirementStatus` is created successfully after commit"
    },
    {
      "commit": "b989dac76eb339f51d4237b451d6249cd27dc207",
      "tree": "d4c3d198a49a2890db866e6e97fd76385781c444",
      "parents": [
        "dd2d941b338098842dc0498c4fcc4a881a1c02ad"
      ],
      "author": {
        "name": "Mridul Pathak",
        "email": "mridul.72@gmail.com",
        "time": "Fri Jul 24 20:30:45 2026 +0530"
      },
      "committer": {
        "name": "GitHub",
        "email": "noreply@github.com",
        "time": "Fri Jul 24 20:30:45 2026 +0530"
      },
      "message": "Fixed: E-commerce search and product detail no longer leak products across catalogs (OFBIZ-4755) (#1499)\n\nFixed: E-commerce search and product detail no longer leak products\nacross catalogs\n(OFBIZ-4755)\n\nKeywordSearch.groovy now sets SEARCH_CATALOG_ID from the current catalog\nbefore processSearchParameters runs, so a catalog with no PCCT_VIEW_ALLW\ncategory configured no longer defaults to searching every catalog in the\nsystem.\n\nProduct.groovy applies the same idea to product-detail viewing: when no\nView-Allow category is configured, a product is only shown if it belongs\nto some catalog of the current product store, preventing direct links to\nproducts that exist solely in an unrelated store\u0027s catalog while leaving\nlegitimate cross-catalog sharing within a store untouched.\n\nThanks: Jeremy Olmstead for reporting the issue."
    },
    {
      "commit": "dd2d941b338098842dc0498c4fcc4a881a1c02ad",
      "tree": "2c76aa5bcb032b831a8b0135bdcc77b0939ff733",
      "parents": [
        "84858b529deef5f9b214dc5129242436c0735a69"
      ],
      "author": {
        "name": "Divesh Dutta",
        "email": "124163540+diveshdut@users.noreply.github.com",
        "time": "Fri Jul 24 20:28:40 2026 +0530"
      },
      "committer": {
        "name": "GitHub",
        "email": "noreply@github.com",
        "time": "Fri Jul 24 20:28:40 2026 +0530"
      },
      "message": "OFBIZ-13463: Fixed false late flag on REQUIRED_MRP proposed supply in MRP engine (#1485)\n\n# Jira Ticket:\n\nhttps://issues.apache.org/jira/browse/OFBIZ-13463\n\n## Summary\n\nFixed a false `isLate \u003d Y` condition for proposed MRP supply generated\nfrom stock-policy replenishment markers.\n\nMRP creates an internal replenishment trigger when current QOH is below\n`ProductFacility.minimumStock`, then immediately creates proposed\nsupply. The proposed requirement start date can be a few milliseconds\nearlier than the MRP run timestamp, which caused the proposed supply\nevent to be incorrectly marked late.\n\nThis change prevents that false late classification for `REQUIRED_MRP`-\ndriven proposed supply while preserving the existing late behavior for\nreal late demand/supply situations.\n\n## Changes\n\n- added a small helper in `MrpServices` to evaluate whether a proposed\norder should be late\n- excluded `REQUIRED_MRP` source events from proposed-order late\nclassification\n- kept the original timestamp-based late behavior for non-`REQUIRED_MRP`\nsource events\n- added dedicated MRP regression tests\n- added a dedicated manufacturing MRP test suite registration"
    },
    {
      "commit": "84858b529deef5f9b214dc5129242436c0735a69",
      "tree": "5fefa4dc0e5f1442089d8002e0d5419a1d4709cb",
      "parents": [
        "2c5ae5ad013af220371a5c4db6b83c85c68a480d"
      ],
      "author": {
        "name": "Divesh Dutta",
        "email": "124163540+diveshdut@users.noreply.github.com",
        "time": "Fri Jul 24 19:07:16 2026 +0530"
      },
      "committer": {
        "name": "GitHub",
        "email": "noreply@github.com",
        "time": "Fri Jul 24 19:07:16 2026 +0530"
      },
      "message": "OFBIZ-13459: Preserve facility context on MRP events \n\n## Jira Ticket:\nhttps://issues.apache.org/jira/browse/OFBIZ-13459\n\n## Summary\n\nThis PR preserves known facility context on generated `MrpEvent` rows\nwhen the OFBiz MRP engine already has reliable facility information\navailable from source data or the current run context.\n\nThe goal is to improve planner traceability without changing MRP\ncalculation behavior, `MrpEvent` identity, or `MrpEvent` merge\nsemantics.\n\n## Problem\n\nToday, some MRP events are created without `facilityId` even when the\nengine already knows the relevant warehouse or manufacturing facility.\n\nThat makes planner-facing event interpretation harder, especially for:\n- product-plus-facility event timelines\n- proposed supply traceability\n- exception analysis\n- API/UI consumers that need concrete facility context on each event\n\n## What This PR Changes\n\nThis PR preserves facility context for these event paths when the engine\nalready has it:\n- `SALES_ORDER_SHIP`\n- `PROD_REQ_RECP`\n- `PUR_ORDER_RECP`\n- `MANUF_ORDER_REQ`\n- `MANUF_ORDER_RECP`\n- `REQUIRED_MRP`\n- `MRP_REQUIREMENT`\n- `PROP_PUR_O_RECP`\n- `PROP_MANUF_O_RECP`\n- `ERROR`\n\nIt also adds a conservative merge-side backfill:\n- if an existing `MrpEvent` row has an empty `facilityId`\n- and a later matching update provides a non-empty `facilityId`\n- then the missing facility is filled in\n- existing facility values are not overwritten\n\n## Important Non-Goals\n\nThis PR does not:\n- change MRP quantity calculation\n- change `MrpEvent` primary key\n- change `MrpEvent` merge semantics\n- force facility assignment for organization-level signals\n- change late-flag behavior\n- include run-log or planner API work\n\n## Facility Group Note\n\nWhen MRP is launched with `facilityGroupId`, current code resolves the\nrun into concrete facilities before event creation.\n\nThis PR preserves those resolved concrete facilities on generated\n`MrpEvent` rows. It does not stamp the facility group id itself.\n\n## Why Event-Level Facility Still Matters\n\nRun-level provenance and event-level facility serve different purposes.\n\nA run may have an overall planning context, but individual events can\nstill belong to different concrete facilities within that run context,\nespecially across warehouse-oriented and manufacturing-oriented event\ntypes."
    },
    {
      "commit": "2c5ae5ad013af220371a5c4db6b83c85c68a480d",
      "tree": "b9e3f4086f7f154bd4e8f98f90104e66df60ee6d",
      "parents": [
        "dda00100d376993d889112d98e77532f03c8b681"
      ],
      "author": {
        "name": "Mridul Pathak",
        "email": "mridul.pathak@hotwaxsystems.com",
        "time": "Fri Jul 03 18:36:19 2026 +0530"
      },
      "committer": {
        "name": "Mridul Pathak",
        "email": "mridul.72@gmail.com",
        "time": "Fri Jul 24 14:20:33 2026 +0530"
      },
      "message": "Fixed: EntityExpr no longer hardcodes the \"default\" delegator when validating condition types (OFBIZ-5100)\n\nEntityExpr.checkRhsType() always resolved DelegatorFactory.getDelegator(\"default\")\ninstead of using the delegator actually running the query, so any setup using a\nnon-\"default\"-named delegator could throw GenericEntityException when building a\nWHERE clause. The real delegator was already available at every call site in\nGenericDAO; it just wasn\u0027t being passed down.\n\nThreads the real Delegator through EntityCondition.makeWhereString(...) as a new\nbackward-compatible default method, and forwards it through every condition type\nthat wraps or combines other conditions (EntityConditionList, EntityFieldMap,\nEntityNotCondition, EntityConditionBuilder) down to EntityExpr.checkRhsType(),\nwhich now skips RHS type validation instead of guessing at \"default\" when no\ndelegator is available.\n"
    },
    {
      "commit": "dda00100d376993d889112d98e77532f03c8b681",
      "tree": "3b54c68542c79e325e4c030f98290f61af7c47a2",
      "parents": [
        "c7853869aa35989e96fd6708117e5548c66dcc6c"
      ],
      "author": {
        "name": "Mridul Pathak",
        "email": "mridul.pathak@hotwaxsystems.com",
        "time": "Wed Jul 22 19:21:07 2026 +0530"
      },
      "committer": {
        "name": "Mridul Pathak",
        "email": "mridul.72@gmail.com",
        "time": "Fri Jul 24 13:50:18 2026 +0530"
      },
      "message": "Remove defunct eBay integration and its references (OFBIZ-13454)\n"
    },
    {
      "commit": "c7853869aa35989e96fd6708117e5548c66dcc6c",
      "tree": "9c1136df0bae5ff2055172a21d6ffe6bac513f4f",
      "parents": [
        "62412c5aa66d39bd5f71d4b3ebea0788c8952036"
      ],
      "author": {
        "name": "Mridul Pathak",
        "email": "mridul.pathak@hotwaxsystems.com",
        "time": "Thu Jul 23 20:30:51 2026 +0530"
      },
      "committer": {
        "name": "Mridul Pathak",
        "email": "mridul.72@gmail.com",
        "time": "Fri Jul 24 13:43:01 2026 +0530"
      },
      "message": "Fixed: Never let entity import move a SequenceValueItem counter backward (OFBIZ-5259)\n\nEntitySaxReader now prevents re-import of stale SequenceValueItem rows from\nregressing sequence counters. When an import would move a SequenceValueItem\u0027s\nseqId backward (detected by comparing incoming seqId to current database\nvalue), the import is skipped and a warning is logged.\n\nBehavior change applies only to the SequenceValueItem entity -- all other\nentities are unaffected. DELETE actions are excluded from the guard, and so\nare checkDataOnly (verify) runs, which still need to surface the would-be\nmismatch instead of silently skipping over it.\n"
    },
    {
      "commit": "62412c5aa66d39bd5f71d4b3ebea0788c8952036",
      "tree": "dbe0fac04b5795a5a2c8bf40c18b0120e2967065",
      "parents": [
        "7225b3bf20688cf977c5dad942efbd3e0cacba3a"
      ],
      "author": {
        "name": "Mridul Pathak",
        "email": "mridul.pathak@hotwaxsystems.com",
        "time": "Thu Jul 23 20:30:29 2026 +0530"
      },
      "committer": {
        "name": "Mridul Pathak",
        "email": "mridul.72@gmail.com",
        "time": "Fri Jul 24 13:43:01 2026 +0530"
      },
      "message": "Added: Optional disableEeca attribute to entity import services (OFBIZ-5259)\n\nExpose a disableEeca attribute on parseEntityXmlFile, entityImport, and\nentityImportDir (default off, no behavior change unless set) that calls\nthe existing EntitySaxReader.setDisableEeca(true) to skip Entity Change\nActions while the import runs. Add a corresponding checkbox and tooltip\nwarning to the EntityImport and EntityImportDir webtools screens.\n\nThis gives operators explicit control for full-instance snapshot\nrestores, where ECA side effects (e.g. order status changes triggered\nby importing OrderPaymentPreference) are unwanted.\n"
    },
    {
      "commit": "7225b3bf20688cf977c5dad942efbd3e0cacba3a",
      "tree": "14e0456d63db156ba144a967f3356fe2c37f84fe",
      "parents": [
        "bcb592869af25805e915cfeb84b5a0d6701e3c3e"
      ],
      "author": {
        "name": "dependabot[bot]",
        "email": "49699333+dependabot[bot]@users.noreply.github.com",
        "time": "Wed Jul 22 13:59:20 2026 +0000"
      },
      "committer": {
        "name": "Jacopo Cappellato",
        "email": "jacopo.cappellato@gmail.com",
        "time": "Wed Jul 22 16:36:22 2026 +0200"
      },
      "message": "Bump swagger-ui-dist from 5.32.10 to 5.32.11 in /framework/rest-api\n\nBumps [swagger-ui-dist](https://github.com/swagger-api/swagger-ui) from 5.32.10 to 5.32.11.\n- [Release notes](https://github.com/swagger-api/swagger-ui/releases)\n- [Commits](https://github.com/swagger-api/swagger-ui/compare/v5.32.10...v5.32.11)\n\n---\nupdated-dependencies:\n- dependency-name: swagger-ui-dist\n  dependency-version: 5.32.11\n  dependency-type: direct:production\n  update-type: version-update:semver-patch\n...\n\nSigned-off-by: dependabot[bot] \u003csupport@github.com\u003e"
    },
    {
      "commit": "bcb592869af25805e915cfeb84b5a0d6701e3c3e",
      "tree": "cf68a2b46d407720c5a450cfadf3e173fb3e1ec4",
      "parents": [
        "ef83cbfd0c57767bcfa059bb52df0638b24f5e8b"
      ],
      "author": {
        "name": "Jacopo Cappellato",
        "email": "jacopo.cappellato@gmail.com",
        "time": "Wed Jul 22 15:07:27 2026 +0200"
      },
      "committer": {
        "name": "Jacopo Cappellato",
        "email": "jacopo.cappellato@gmail.com",
        "time": "Wed Jul 22 16:28:22 2026 +0200"
      },
      "message": "Bump github/codeql-action/init and  github/codeql-action/analyze from 4.37.1 to 4.37.3\n"
    },
    {
      "commit": "ef83cbfd0c57767bcfa059bb52df0638b24f5e8b",
      "tree": "c0fbee7197bb710520f6f41617e205f7b1d3ca08",
      "parents": [
        "cc64f5144e807d616da577ee9d0d15f0a12effb4"
      ],
      "author": {
        "name": "dependabot[bot]",
        "email": "49699333+dependabot[bot]@users.noreply.github.com",
        "time": "Wed Jul 22 11:34:34 2026 +0000"
      },
      "committer": {
        "name": "Jacopo Cappellato",
        "email": "jacopo.cappellato@gmail.com",
        "time": "Wed Jul 22 16:28:22 2026 +0200"
      },
      "message": "Bump github/codeql-action/autobuild from 4.37.1 to 4.37.3\n\nBumps [github/codeql-action/autobuild](https://github.com/github/codeql-action) from 4.37.1 to 4.37.3.\n- [Release notes](https://github.com/github/codeql-action/releases)\n- [Changelog](https://github.com/github/codeql-action/blob/main/CHANGELOG.md)\n- [Commits](https://github.com/github/codeql-action/compare/7188fc363630916deb702c7fdcf4e481b751f97a...e4fba868fa4b1b91e1fdab776edc8cfbe6e9fb81)\n\n---\nupdated-dependencies:\n- dependency-name: github/codeql-action/autobuild\n  dependency-version: 4.37.1\n  dependency-type: direct:production\n  update-type: version-update:semver-patch\n...\n\nSigned-off-by: dependabot[bot] \u003csupport@github.com\u003e"
    },
    {
      "commit": "cc64f5144e807d616da577ee9d0d15f0a12effb4",
      "tree": "3455334698d1d339c14a184580c729100d8a654b",
      "parents": [
        "6c5a35ae0088b3fb15e576c18a10ec8418414c03"
      ],
      "author": {
        "name": "Jacopo Cappellato",
        "email": "jacopo.cappellato@gmail.com",
        "time": "Wed Jul 22 10:53:36 2026 +0200"
      },
      "committer": {
        "name": "Jacopo Cappellato",
        "email": "jacopo.cappellato@gmail.com",
        "time": "Wed Jul 22 12:56:22 2026 +0200"
      },
      "message": "Bump github/codeql-action/analyze from 4.37.0 to 4.37.1\n"
    },
    {
      "commit": "6c5a35ae0088b3fb15e576c18a10ec8418414c03",
      "tree": "198b72785663fd702b039d03044183e490141a98",
      "parents": [
        "b18a707d547bb8289492fef0055b43aabde0b232"
      ],
      "author": {
        "name": "Jacopo Cappellato",
        "email": "jacopo.cappellato@gmail.com",
        "time": "Wed Jul 22 10:52:43 2026 +0200"
      },
      "committer": {
        "name": "Jacopo Cappellato",
        "email": "jacopo.cappellato@gmail.com",
        "time": "Wed Jul 22 12:56:22 2026 +0200"
      },
      "message": "Bump github/codeql-action/autobuild from 4.37.0 to 4.37.1\n"
    },
    {
      "commit": "b18a707d547bb8289492fef0055b43aabde0b232",
      "tree": "56bc4a77b82e251d687d7784f2e9e9e1d9b8a667",
      "parents": [
        "c20f65657364cfc148df01afa4c51a9031660c63"
      ],
      "author": {
        "name": "dependabot[bot]",
        "email": "49699333+dependabot[bot]@users.noreply.github.com",
        "time": "Fri Jul 17 13:34:17 2026 +0000"
      },
      "committer": {
        "name": "Jacopo Cappellato",
        "email": "jacopo.cappellato@gmail.com",
        "time": "Wed Jul 22 12:56:22 2026 +0200"
      },
      "message": "Bump github/codeql-action/init from 4.37.0 to 4.37.1\n\nBumps [github/codeql-action/init](https://github.com/github/codeql-action) from 4.37.0 to 4.37.1.\n- [Release notes](https://github.com/github/codeql-action/releases)\n- [Changelog](https://github.com/github/codeql-action/blob/main/CHANGELOG.md)\n- [Commits](https://github.com/github/codeql-action/compare/99df26d4f13ea111d4ec1a7dddef6063f76b97e9...7188fc363630916deb702c7fdcf4e481b751f97a)\n\n---\nupdated-dependencies:\n- dependency-name: github/codeql-action/init\n  dependency-version: 4.37.1\n  dependency-type: direct:production\n  update-type: version-update:semver-patch\n...\n\nSigned-off-by: dependabot[bot] \u003csupport@github.com\u003e"
    },
    {
      "commit": "c20f65657364cfc148df01afa4c51a9031660c63",
      "tree": "f16970adb7d8d687e95919c52d0011b884227d69",
      "parents": [
        "d06b07b9f4428f12c1ff6941bae538b5cf065763"
      ],
      "author": {
        "name": "Jacopo Cappellato",
        "email": "jacopo.cappellato@gmail.com",
        "time": "Wed Jul 22 09:14:56 2026 +0200"
      },
      "committer": {
        "name": "Jacopo Cappellato",
        "email": "jacopo.cappellato@gmail.com",
        "time": "Wed Jul 22 09:55:00 2026 +0200"
      },
      "message": "Bump fast-xml-parser to 5.10.1 and dompurify to 3.4.12\n\nThese are transitive dependencies introduced via redoc 2.5.3. The upgrade fixes 2 security alerts by Dependabot.\n"
    },
    {
      "commit": "d06b07b9f4428f12c1ff6941bae538b5cf065763",
      "tree": "779cf98142c54cfd56201414fd0ca21918db8b94",
      "parents": [
        "a0f034018541e2361c9348c08b8ec6f964b5c032"
      ],
      "author": {
        "name": "dependabot[bot]",
        "email": "49699333+dependabot[bot]@users.noreply.github.com",
        "time": "Mon Jul 20 13:38:47 2026 +0000"
      },
      "committer": {
        "name": "Jacopo Cappellato",
        "email": "jacopo.cappellato@gmail.com",
        "time": "Wed Jul 22 09:27:24 2026 +0200"
      },
      "message": "Bump moment-timezone in /themes/common-theme/webapp/common-theme/js\n\nBumps [moment-timezone](https://github.com/moment/moment-timezone) from 0.6.2 to 0.6.3.\n- [Release notes](https://github.com/moment/moment-timezone/releases)\n- [Changelog](https://github.com/moment/moment-timezone/blob/develop/changelog.md)\n- [Commits](https://github.com/moment/moment-timezone/compare/0.6.2...0.6.3)\n\n---\nupdated-dependencies:\n- dependency-name: moment-timezone\n  dependency-version: 0.6.3\n  dependency-type: direct:production\n  update-type: version-update:semver-patch\n...\n\nSigned-off-by: dependabot[bot] \u003csupport@github.com\u003e"
    },
    {
      "commit": "a0f034018541e2361c9348c08b8ec6f964b5c032",
      "tree": "031fa5c96017adedead83755c821b4000b496d01",
      "parents": [
        "4b83b016c48b8ad45567da732295865092ea595a"
      ],
      "author": {
        "name": "dependabot[bot]",
        "email": "49699333+dependabot[bot]@users.noreply.github.com",
        "time": "Tue Jul 21 13:34:47 2026 +0000"
      },
      "committer": {
        "name": "Jacopo Cappellato",
        "email": "jacopo.cappellato@gmail.com",
        "time": "Wed Jul 22 09:26:09 2026 +0200"
      },
      "message": "Bump swagger-ui-dist from 5.32.8 to 5.32.10 in /framework/rest-api\n\nBumps [swagger-ui-dist](https://github.com/swagger-api/swagger-ui) from 5.32.8 to 5.32.10.\n- [Release notes](https://github.com/swagger-api/swagger-ui/releases)\n- [Commits](https://github.com/swagger-api/swagger-ui/compare/v5.32.8...v5.32.10)\n\n---\nupdated-dependencies:\n- dependency-name: swagger-ui-dist\n  dependency-version: 5.32.10\n  dependency-type: direct:production\n  update-type: version-update:semver-patch\n...\n\nSigned-off-by: dependabot[bot] \u003csupport@github.com\u003e"
    },
    {
      "commit": "4b83b016c48b8ad45567da732295865092ea595a",
      "tree": "95ae6ddc73c49d71d90d89cd87754f8949ea5953",
      "parents": [
        "1c73a9485d6cf46494854697fe30f6895bdfebe0"
      ],
      "author": {
        "name": "Jacopo Cappellato",
        "email": "jacopo.cappellato@gmail.com",
        "time": "Wed Jul 22 08:38:09 2026 +0200"
      },
      "committer": {
        "name": "Jacopo Cappellato",
        "email": "jacopo.cappellato@gmail.com",
        "time": "Wed Jul 22 09:06:57 2026 +0200"
      },
      "message": "Bump js-yaml to 4.3.0 and brace-expansion to 2.1.2\n\nThese are transitive dependencies introduced via redoc 2.5.3. The upgrade fixes 2 security alerts by Dependabot.\n"
    },
    {
      "commit": "1c73a9485d6cf46494854697fe30f6895bdfebe0",
      "tree": "0ec6bdbb1730316a6d7122b7c780330710895bb1",
      "parents": [
        "655cf5aa1705bd551475461b66c4066c2a678971"
      ],
      "author": {
        "name": "dependabot[bot]",
        "email": "49699333+dependabot[bot]@users.noreply.github.com",
        "time": "Tue Jul 21 13:34:08 2026 +0000"
      },
      "committer": {
        "name": "Jacopo Cappellato",
        "email": "jacopo.cappellato@gmail.com",
        "time": "Tue Jul 21 16:05:22 2026 +0200"
      },
      "message": "Bump actions/checkout from 7.0.0 to 7.0.1\n\nBumps [actions/checkout](https://github.com/actions/checkout) from 7.0.0 to 7.0.1.\n- [Release notes](https://github.com/actions/checkout/releases)\n- [Changelog](https://github.com/actions/checkout/blob/main/CHANGELOG.md)\n- [Commits](https://github.com/actions/checkout/compare/9c091bb21b7c1c1d1991bb908d89e4e9dddfe3e0...3d3c42e5aac5ba805825da76410c181273ba90b1)\n\n---\nupdated-dependencies:\n- dependency-name: actions/checkout\n  dependency-version: 7.0.1\n  dependency-type: direct:production\n  update-type: version-update:semver-patch\n...\n\nSigned-off-by: dependabot[bot] \u003csupport@github.com\u003e"
    },
    {
      "commit": "655cf5aa1705bd551475461b66c4066c2a678971",
      "tree": "30897302675e020eb2a4300d7603d796a8455a22",
      "parents": [
        "3050ccf4aa5cfcda819a5a76fae21b1a2ef96453"
      ],
      "author": {
        "name": "Ashish Vijaywargiya",
        "email": "ashish@apache.org",
        "time": "Mon Jul 20 23:17:36 2026 +0530"
      },
      "committer": {
        "name": "GitHub",
        "email": "noreply@github.com",
        "time": "Mon Jul 20 23:17:36 2026 +0530"
      },
      "message": "Migrate remaining minilang XML tests to Groovy JUnit test cases (#1473)"
    },
    {
      "commit": "3050ccf4aa5cfcda819a5a76fae21b1a2ef96453",
      "tree": "68571f91e3240ede8aca44e3d880b419871046e0",
      "parents": [
        "d9f7d79a264331b6223d5fb75b847b400a3ae97a"
      ],
      "author": {
        "name": "Ashish Vijaywargiya",
        "email": "ashish@apache.org",
        "time": "Mon Jul 20 17:10:55 2026 +0530"
      },
      "committer": {
        "name": "GitHub",
        "email": "noreply@github.com",
        "time": "Mon Jul 20 17:10:55 2026 +0530"
      },
      "message": "Fixing the issue with the CI/CD (#1470)\n\nGitHub Actions doesn\u0027t expose the context to , so the\nrelease*-skips-JDK-21 condition broke workflow parsing entirely (0 jobs\nrun); shrinking the matrix itself in a prep job avoids that restriction."
    },
    {
      "commit": "d9f7d79a264331b6223d5fb75b847b400a3ae97a",
      "tree": "c6790d8b2a058c91dd447a05e8bca0b5b375276e",
      "parents": [
        "2bc6eefafc91857d2de72c968e1b197790f5451d"
      ],
      "author": {
        "name": "dependabot[bot]",
        "email": "49699333+dependabot[bot]@users.noreply.github.com",
        "time": "Fri Jul 17 13:34:23 2026 +0000"
      },
      "committer": {
        "name": "Jacopo Cappellato",
        "email": "jacopo.cappellato@gmail.com",
        "time": "Sun Jul 19 15:48:40 2026 +0200"
      },
      "message": "Bump actions/setup-java from 5.5.0 to 5.6.0\n\nBumps [actions/setup-java](https://github.com/actions/setup-java) from 5.5.0 to 5.6.0.\n- [Release notes](https://github.com/actions/setup-java/releases)\n- [Commits](https://github.com/actions/setup-java/compare/0f481fcb613427c0f801b606911222b5b6f3083a...03ad4de0992f5dab5e18fcb136590ce7c4a0ac95)\n\n---\nupdated-dependencies:\n- dependency-name: actions/setup-java\n  dependency-version: 5.6.0\n  dependency-type: direct:production\n  update-type: version-update:semver-minor\n...\n\nSigned-off-by: dependabot[bot] \u003csupport@github.com\u003e"
    },
    {
      "commit": "2bc6eefafc91857d2de72c968e1b197790f5451d",
      "tree": "957f88ab5cf4954c90a052f607f1a0d11ef5ad50",
      "parents": [
        "6103826dc59a03a0954ec6c42b758ef1a5758e84"
      ],
      "author": {
        "name": "Arun Patidar",
        "email": "arun.patidar@hotwax.co",
        "time": "Fri Jul 17 15:36:24 2026 +0530"
      },
      "committer": {
        "name": "GitHub",
        "email": "noreply@github.com",
        "time": "Fri Jul 17 15:36:24 2026 +0530"
      },
      "message": "Fixed: CSV exports generated from screens using the form macro renderer rendered a trailing comma at the end of every row, causing empty trailing columns (OFBIZ-12223) (#1450)\n\nFixed: CSV exports generated from screens using the form macro renderer\nrendered a trailing comma at the end of every row, causing empty\ntrailing columns (OFBIZ-12223)\n\nExplanation: To resolve this:\n- Introduced a tracker state and a helper macro inside\nCsvFormMacroLibrary.ftl.\n- Reset the comma tracker at the start of each row inside  and .\n- Configured cell-level open macros (, , etc.) to prepend a comma\nstarting from the second cell of each row.\n- Removed the hardcoded trailing commas from individual field macros\n(such as , , and ) to decouple column layout delimiters from field\ncontent rendering.\n\nThanks:  Benjamin Jugl for reporting issue."
    },
    {
      "commit": "6103826dc59a03a0954ec6c42b758ef1a5758e84",
      "tree": "46626c77ed895311c120a79e6be802df9ca570fa",
      "parents": [
        "6e5176f8187de9d2fefa84ccc379f49438a426c2"
      ],
      "author": {
        "name": "Ashish Vijaywargiya",
        "email": "ashish@apache.org",
        "time": "Thu Jul 16 15:26:54 2026 +0530"
      },
      "committer": {
        "name": "GitHub",
        "email": "noreply@github.com",
        "time": "Thu Jul 16 15:26:54 2026 +0530"
      },
      "message": "Since Release24.09 still runs on Java 17, we\u0027ve rolled trunk\u0027s compile target back to Java 17 while keeping it tested on Java 21 too.\n\nSince Release24.09 still runs on Java 17, we\u0027ve rolled trunk\u0027s compile target back to Java 17 while keeping it tested on Java 21 too.\n\nSummary:\n\n1) build.gradle and gradle.yml now target Java 17 again (bytecode, javadoc, CI). Please refer how I have used metrix support in gradle.yml file.\n\n2) CI now runs a JDK matrix (17 and 21) on every push/PR, skipping 21 for release* branches.\n\n3) Reverted Java 19+ only calls (Locale.of, Thread.threadId) back to their pre-19 equivalents across 16 files, since JDK 17 doesn\u0027t have them.\n\n4) Confirmed those older calls are only \"deprecated,\" not \"removed,\" so they\u0027re safe on both JDK versions.\n\n5) Cleaned up all resulting compiler warnings with narrowly-scoped @SuppressWarnings(\"deprecation\").\n\n6) Also caught and reverted two committed secret values in security.properties back to blank.\n\n7) Ran the full unit test suite (423 tests) on both JDK 17 and JDK 21 — 0 warnings, 0 failures on both."
    },
    {
      "commit": "6e5176f8187de9d2fefa84ccc379f49438a426c2",
      "tree": "24b76cf6b56acdeac59bd73da1778dc379a66e4f",
      "parents": [
        "e9fc437ccb0631aa4d670221e59d9a4938d856ba"
      ],
      "author": {
        "name": "dependabot[bot]",
        "email": "49699333+dependabot[bot]@users.noreply.github.com",
        "time": "Wed Jul 15 13:35:17 2026 +0000"
      },
      "committer": {
        "name": "Jacopo Cappellato",
        "email": "jacopo.cappellato@gmail.com",
        "time": "Wed Jul 15 15:45:28 2026 +0200"
      },
      "message": "Bump github/codeql-action/upload-sarif\n\nBumps [github/codeql-action/upload-sarif](https://github.com/github/codeql-action) from f133996fb588ff4e83f1e1d4911404720ac9cb17 to e58424170fb0262c8d7ed60a2e84b9bffe205c67.\n- [Release notes](https://github.com/github/codeql-action/releases)\n- [Changelog](https://github.com/github/codeql-action/blob/main/CHANGELOG.md)\n- [Commits](https://github.com/github/codeql-action/compare/f133996fb588ff4e83f1e1d4911404720ac9cb17...e58424170fb0262c8d7ed60a2e84b9bffe205c67)\n\n---\nupdated-dependencies:\n- dependency-name: github/codeql-action/upload-sarif\n  dependency-version: e58424170fb0262c8d7ed60a2e84b9bffe205c67\n  dependency-type: direct:production\n...\n\nSigned-off-by: dependabot[bot] \u003csupport@github.com\u003e"
    },
    {
      "commit": "e9fc437ccb0631aa4d670221e59d9a4938d856ba",
      "tree": "7a367c3657308957894e3de12632b156899c318d",
      "parents": [
        "58ba08cf5e463a808b34da84a70a6a8fbfd734a2"
      ],
      "author": {
        "name": "dependabot[bot]",
        "email": "49699333+dependabot[bot]@users.noreply.github.com",
        "time": "Mon Jul 13 13:34:08 2026 +0000"
      },
      "committer": {
        "name": "Jacopo Cappellato",
        "email": "jacopo.cappellato@gmail.com",
        "time": "Wed Jul 15 12:24:46 2026 +0200"
      },
      "message": "Bump dompurify in /themes/common-theme/webapp/common-theme/js\n\nBumps [dompurify](https://github.com/cure53/DOMPurify) from 3.4.11 to 3.4.12.\n- [Release notes](https://github.com/cure53/DOMPurify/releases)\n- [Commits](https://github.com/cure53/DOMPurify/compare/3.4.11...3.4.12)\n\n---\nupdated-dependencies:\n- dependency-name: dompurify\n  dependency-version: 3.4.12\n  dependency-type: direct:production\n  update-type: version-update:semver-patch\n...\n\nSigned-off-by: dependabot[bot] \u003csupport@github.com\u003e"
    },
    {
      "commit": "58ba08cf5e463a808b34da84a70a6a8fbfd734a2",
      "tree": "73b7f29c5e455279c29bfa5cb69e483247c270c0",
      "parents": [
        "eae78ba29a67e556735399c639595293734a6e1a"
      ],
      "author": {
        "name": "dependabot[bot]",
        "email": "49699333+dependabot[bot]@users.noreply.github.com",
        "time": "Tue Jul 14 13:35:16 2026 +0000"
      },
      "committer": {
        "name": "Jacopo Cappellato",
        "email": "jacopo.cappellato@gmail.com",
        "time": "Wed Jul 15 07:55:07 2026 +0200"
      },
      "message": "Bump github/codeql-action/upload-sarif\n\nBumps [github/codeql-action/upload-sarif](https://github.com/github/codeql-action) from 8096e4f9571939c23cbd19018c44c665f90096af to f133996fb588ff4e83f1e1d4911404720ac9cb17.\n- [Release notes](https://github.com/github/codeql-action/releases)\n- [Changelog](https://github.com/github/codeql-action/blob/main/CHANGELOG.md)\n- [Commits](https://github.com/github/codeql-action/compare/8096e4f9571939c23cbd19018c44c665f90096af...f133996fb588ff4e83f1e1d4911404720ac9cb17)\n\n---\nupdated-dependencies:\n- dependency-name: github/codeql-action/upload-sarif\n  dependency-version: f133996fb588ff4e83f1e1d4911404720ac9cb17\n  dependency-type: direct:production\n...\n\nSigned-off-by: dependabot[bot] \u003csupport@github.com\u003e"
    },
    {
      "commit": "eae78ba29a67e556735399c639595293734a6e1a",
      "tree": "b412445a0f7ba8c327b89bec0563638d4321b244",
      "parents": [
        "6ff770d89275bc36e63f91a11ad10bbc4e0eb86e"
      ],
      "author": {
        "name": "dependabot[bot]",
        "email": "49699333+dependabot[bot]@users.noreply.github.com",
        "time": "Mon Jul 13 13:37:39 2026 +0000"
      },
      "committer": {
        "name": "Jacopo Cappellato",
        "email": "jacopo.cappellato@gmail.com",
        "time": "Mon Jul 13 18:08:50 2026 +0200"
      },
      "message": "Bump github/codeql-action/upload-sarif\n\nBumps [github/codeql-action/upload-sarif](https://github.com/github/codeql-action) from 29c712e0b7e56a70523cddd70c2cb49d3e3eb717 to 8096e4f9571939c23cbd19018c44c665f90096af.\n- [Release notes](https://github.com/github/codeql-action/releases)\n- [Changelog](https://github.com/github/codeql-action/blob/main/CHANGELOG.md)\n- [Commits](https://github.com/github/codeql-action/compare/29c712e0b7e56a70523cddd70c2cb49d3e3eb717...8096e4f9571939c23cbd19018c44c665f90096af)\n\n---\nupdated-dependencies:\n- dependency-name: github/codeql-action/upload-sarif\n  dependency-version: 8096e4f9571939c23cbd19018c44c665f90096af\n  dependency-type: direct:production\n...\n\nSigned-off-by: dependabot[bot] \u003csupport@github.com\u003e"
    },
    {
      "commit": "6ff770d89275bc36e63f91a11ad10bbc4e0eb86e",
      "tree": "1950841b9bb51e8a0835ebd36a6dca24dcf585a8",
      "parents": [
        "7bc2f9c037d1c3c52b5b305d62025a51c34938e2"
      ],
      "author": {
        "name": "Ravi Lodhi",
        "email": "40700208+ravilodhi@users.noreply.github.com",
        "time": "Fri Jul 10 20:21:24 2026 +0530"
      },
      "committer": {
        "name": "GitHub",
        "email": "noreply@github.com",
        "time": "Fri Jul 10 20:21:24 2026 +0530"
      },
      "message": "Implemented: Added Add Invoice Attribute functionality (OFBIZ-12420). (#1451)\n\nImplemented: Added Add Invoice Attribute functionality (OFBIZ-12420)\n\nThanks Pierre Smits and Ravi Lodhi for your contribution."
    },
    {
      "commit": "7bc2f9c037d1c3c52b5b305d62025a51c34938e2",
      "tree": "a2123d81e48552832ada88c95c28b001abba4749",
      "parents": [
        "50301faea345b48d45f6886f2de8123177bf5b12"
      ],
      "author": {
        "name": "Ravi Lodhi",
        "email": "40700208+ravilodhi@users.noreply.github.com",
        "time": "Fri Jul 10 19:45:52 2026 +0530"
      },
      "committer": {
        "name": "GitHub",
        "email": "noreply@github.com",
        "time": "Fri Jul 10 19:45:52 2026 +0530"
      },
      "message": "Improved: Moved FinAccount title to above FinAccountTabBar for UI consistency (OFBIZ-13018). (#1449)\n\nImproved: Moved FinAccount title to above FinAccountTabBar for UI\nconsistency (OFBIZ-13018).\n\nThanks  Pierre Smits and Ravi Lodhi for your contribution."
    },
    {
      "commit": "50301faea345b48d45f6886f2de8123177bf5b12",
      "tree": "235a9232a62030db2bab5070b7931adaedd84fa4",
      "parents": [
        "8f252896ec6304958f4afbd6f18948ea5e892a13"
      ],
      "author": {
        "name": "dependabot[bot]",
        "email": "49699333+dependabot[bot]@users.noreply.github.com",
        "time": "Fri Jul 10 13:35:14 2026 +0000"
      },
      "committer": {
        "name": "Jacopo Cappellato",
        "email": "jacopo.cappellato@gmail.com",
        "time": "Fri Jul 10 15:44:21 2026 +0200"
      },
      "message": "Bump github/codeql-action/upload-sarif\n\n---\nupdated-dependencies:\n- dependency-name: github/codeql-action/upload-sarif\n  dependency-version: 29c712e0b7e56a70523cddd70c2cb49d3e3eb717\n  dependency-type: direct:production\n...\n\nSigned-off-by: dependabot[bot] \u003csupport@github.com\u003e"
    },
    {
      "commit": "8f252896ec6304958f4afbd6f18948ea5e892a13",
      "tree": "f07174a36920312be6bbd117480c3cfda60b44b9",
      "parents": [
        "ade63a8af6afb82e7671cb3bbe985073d2a24532"
      ],
      "author": {
        "name": "chandan-khandelwal",
        "email": "chandan.khandelwal@hotwaxsystems.com",
        "time": "Fri Jul 10 17:58:44 2026 +0530"
      },
      "committer": {
        "name": "GitHub",
        "email": "noreply@github.com",
        "time": "Fri Jul 10 17:58:44 2026 +0530"
      },
      "message": "Fixed: MissingPropertyException when copying quote adjustments in copyQuote service (OFBIZ-13458) (#1446)\n\nFixed: MissingPropertyException when copying quote adjustments in\ncopyQuote service\n(OFBIZ-13458)\n\nThanks Chandan Khandelwal for your contribution"
    },
    {
      "commit": "ade63a8af6afb82e7671cb3bbe985073d2a24532",
      "tree": "583bc9a9b60592a0e2f1e50aeb23753bc56b476c",
      "parents": [
        "6ff5306eeab9f57471e017b923569b3d2c6d8c99"
      ],
      "author": {
        "name": "Nameet Jain",
        "email": "jnameet@gmail.com",
        "time": "Fri Jul 10 15:54:58 2026 +0530"
      },
      "committer": {
        "name": "GitHub",
        "email": "noreply@github.com",
        "time": "Fri Jul 10 15:54:58 2026 +0530"
      },
      "message": "Fixed the display value of allocateInventory on the Store screen.  (#1237)\n\nFixed: Fixed the display value of allocateInventory on the Store screen.\nAllocate Inventory flag is designed to be treated as N. However, on the\nCatalog screen, it shows Y when the flag value is null in the database,\nwhich is confusing. OFBIZ-12001\n\nThanks Ankush Upadhyay and Nameet jain for your contribution."
    },
    {
      "commit": "6ff5306eeab9f57471e017b923569b3d2c6d8c99",
      "tree": "b3d09959ca33e1b47f1150d6a22e5c9f7d2038ba",
      "parents": [
        "971180a2a92049b459b347bb42ce8b69a84f30db"
      ],
      "author": {
        "name": "Nameet Jain",
        "email": "jnameet@gmail.com",
        "time": "Fri Jul 10 15:51:46 2026 +0530"
      },
      "committer": {
        "name": "GitHub",
        "email": "noreply@github.com",
        "time": "Fri Jul 10 15:51:46 2026 +0530"
      },
      "message": "Fixed reservation logic for Auto Inventory allocation process. OFBIZ-13386 (#1254)\n\nFixed reservation logic for Auto Inventory allocation process.\nOFBIZ-13386\n\nThanks  Carsten Heinrigs for reporting the issue, Nameet Jain for verifying and providing PR to fix."
    },
    {
      "commit": "971180a2a92049b459b347bb42ce8b69a84f30db",
      "tree": "423d86a0179375dfc58835f2eeb3897f585e693f",
      "parents": [
        "452d0ba982e87ba492e60b88fcac3ab581bd605b"
      ],
      "author": {
        "name": "dependabot[bot]",
        "email": "49699333+dependabot[bot]@users.noreply.github.com",
        "time": "Thu Jul 09 13:40:34 2026 +0000"
      },
      "committer": {
        "name": "Jacopo Cappellato",
        "email": "jacopo.cappellato@gmail.com",
        "time": "Thu Jul 09 17:44:02 2026 +0200"
      },
      "message": "Bump github/codeql-action/upload-sarif\n\nBumps [github/codeql-action/upload-sarif](https://github.com/github/codeql-action) from 0e974e6288eb18d3c44fbc71007c175f59daab40 to 4581e395f334690391455bc6993ae65775c24332.\n- [Release notes](https://github.com/github/codeql-action/releases)\n- [Changelog](https://github.com/github/codeql-action/blob/main/CHANGELOG.md)\n- [Commits](https://github.com/github/codeql-action/compare/0e974e6288eb18d3c44fbc71007c175f59daab40...4581e395f334690391455bc6993ae65775c24332)\n\n---\nupdated-dependencies:\n- dependency-name: github/codeql-action/upload-sarif\n  dependency-version: 4581e395f334690391455bc6993ae65775c24332\n  dependency-type: direct:production\n...\n\nSigned-off-by: dependabot[bot] \u003csupport@github.com\u003e"
    },
    {
      "commit": "452d0ba982e87ba492e60b88fcac3ab581bd605b",
      "tree": "e8f808f27e7b8d6b4bf6988f98c5ec1515f5e513",
      "parents": [
        "23739ae6aae98b68362dafd3763bb5ffc843d7da"
      ],
      "author": {
        "name": "Jacopo Cappellato",
        "email": "jacopo.cappellato@gmail.com",
        "time": "Thu Jul 09 08:59:48 2026 +0200"
      },
      "committer": {
        "name": "Jacopo Cappellato",
        "email": "jacopo.cappellato@gmail.com",
        "time": "Thu Jul 09 09:42:57 2026 +0200"
      },
      "message": "Bump github/codeql-action/analyze from 4.36.3 to 4.37.0\n"
    },
    {
      "commit": "23739ae6aae98b68362dafd3763bb5ffc843d7da",
      "tree": "2cf1723a9c721b89886757b3e1e80fcbe959710d",
      "parents": [
        "a657362d3eafdb35e4e8daeb3fe5e7f5643992fe"
      ],
      "author": {
        "name": "Jacopo Cappellato",
        "email": "jacopo.cappellato@gmail.com",
        "time": "Thu Jul 09 08:59:23 2026 +0200"
      },
      "committer": {
        "name": "Jacopo Cappellato",
        "email": "jacopo.cappellato@gmail.com",
        "time": "Thu Jul 09 09:42:57 2026 +0200"
      },
      "message": "Bump github/codeql-action/autobuild from 4.36.3 to 4.37.0\n"
    },
    {
      "commit": "a657362d3eafdb35e4e8daeb3fe5e7f5643992fe",
      "tree": "77352649aa7e4cbd73a4dec7476283426e82ac2f",
      "parents": [
        "8f05b771791838025f13f716b70d572cd4ec9cfd"
      ],
      "author": {
        "name": "dependabot[bot]",
        "email": "49699333+dependabot[bot]@users.noreply.github.com",
        "time": "Wed Jul 08 13:36:20 2026 +0000"
      },
      "committer": {
        "name": "Jacopo Cappellato",
        "email": "jacopo.cappellato@gmail.com",
        "time": "Thu Jul 09 09:42:57 2026 +0200"
      },
      "message": "Bump github/codeql-action/init from 4.36.3 to 4.37.0\n\nBumps [github/codeql-action/init](https://github.com/github/codeql-action) from 4.36.3 to 4.37.0.\n- [Release notes](https://github.com/github/codeql-action/releases)\n- [Changelog](https://github.com/github/codeql-action/blob/main/CHANGELOG.md)\n- [Commits](https://github.com/github/codeql-action/compare/54f647b7e1bb85c95cddabcd46b0c578ec92bc1a...99df26d4f13ea111d4ec1a7dddef6063f76b97e9)\n\n---\nupdated-dependencies:\n- dependency-name: github/codeql-action/init\n  dependency-version: 4.37.0\n  dependency-type: direct:production\n  update-type: version-update:semver-minor\n...\n\nSigned-off-by: dependabot[bot] \u003csupport@github.com\u003e"
    },
    {
      "commit": "8f05b771791838025f13f716b70d572cd4ec9cfd",
      "tree": "295a15a877240991c7d646854f52c0ea3f803d67",
      "parents": [
        "d6c19c612e9ef50eb28c2f9c5645e77f6053c84a"
      ],
      "author": {
        "name": "dependabot[bot]",
        "email": "49699333+dependabot[bot]@users.noreply.github.com",
        "time": "Wed Jul 08 13:36:07 2026 +0000"
      },
      "committer": {
        "name": "Jacopo Cappellato",
        "email": "jacopo.cappellato@gmail.com",
        "time": "Wed Jul 08 16:49:25 2026 +0200"
      },
      "message": "Bump github/codeql-action/upload-sarif\n\nBumps [github/codeql-action/upload-sarif](https://github.com/github/codeql-action) from 006d029c8dc7b906d4ce5b7c700d32f20f2d35dd to 0e974e6288eb18d3c44fbc71007c175f59daab40.\n- [Release notes](https://github.com/github/codeql-action/releases)\n- [Changelog](https://github.com/github/codeql-action/blob/main/CHANGELOG.md)\n- [Commits](https://github.com/github/codeql-action/compare/006d029c8dc7b906d4ce5b7c700d32f20f2d35dd...0e974e6288eb18d3c44fbc71007c175f59daab40)\n\n---\nupdated-dependencies:\n- dependency-name: github/codeql-action/upload-sarif\n  dependency-version: 0e974e6288eb18d3c44fbc71007c175f59daab40\n  dependency-type: direct:production\n...\n\nSigned-off-by: dependabot[bot] \u003csupport@github.com\u003e"
    },
    {
      "commit": "d6c19c612e9ef50eb28c2f9c5645e77f6053c84a",
      "tree": "8030161634c4a99286647749d716de7e0ab362f3",
      "parents": [
        "df8fcbc9820e7a4392487fddb8fbc8a14c22e2cc"
      ],
      "author": {
        "name": "dependabot[bot]",
        "email": "49699333+dependabot[bot]@users.noreply.github.com",
        "time": "Wed Jul 08 13:36:43 2026 +0000"
      },
      "committer": {
        "name": "Jacopo Cappellato",
        "email": "jacopo.cappellato@gmail.com",
        "time": "Wed Jul 08 16:04:02 2026 +0200"
      },
      "message": "Bump actions/setup-java from 5.4.0 to 5.5.0\n\nBumps [actions/setup-java](https://github.com/actions/setup-java) from 5.4.0 to 5.5.0.\n- [Release notes](https://github.com/actions/setup-java/releases)\n- [Commits](https://github.com/actions/setup-java/compare/1bcf9fb12cf4aa7d266a90ae39939e61372fe520...0f481fcb613427c0f801b606911222b5b6f3083a)\n\n---\nupdated-dependencies:\n- dependency-name: actions/setup-java\n  dependency-version: 5.5.0\n  dependency-type: direct:production\n  update-type: version-update:semver-minor\n...\n\nSigned-off-by: dependabot[bot] \u003csupport@github.com\u003e"
    },
    {
      "commit": "df8fcbc9820e7a4392487fddb8fbc8a14c22e2cc",
      "tree": "e6664612554f25b597bde01b26f705f9c2349574",
      "parents": [
        "143c04d5f5f17e2380b0d57e4a90dff984acc05c"
      ],
      "author": {
        "name": "Lukas Finster",
        "email": "lukas.finster@ecomify.de",
        "time": "Thu Jun 18 14:54:06 2026 +0200"
      },
      "committer": {
        "name": "Lukas-Finster",
        "email": "lukas.finster@ecomify.de",
        "time": "Wed Jul 08 14:42:40 2026 +0200"
      },
      "message": "Improved: Added basic JUnit test for relevant rest-api classes and\nintegration test for rest-api services (OFBIZ-13443)"
    },
    {
      "commit": "143c04d5f5f17e2380b0d57e4a90dff984acc05c",
      "tree": "3c485f3857c29c5449da329e8cb2b6abb587aa1b",
      "parents": [
        "93de9a21f5cfbd36208a7aed06ea9b2869bc61a7"
      ],
      "author": {
        "name": "Lukas Finster",
        "email": "lukas.finster@ecomify.de",
        "time": "Thu Jul 02 13:13:37 2026 +0200"
      },
      "committer": {
        "name": "Lukas-Finster",
        "email": "lukas.finster@ecomify.de",
        "time": "Wed Jul 08 14:42:40 2026 +0200"
      },
      "message": "Fix: Guard against NPE in ModelApiReader when service Element is missing in ModelResource (OFBIZ-13443)\n"
    },
    {
      "commit": "93de9a21f5cfbd36208a7aed06ea9b2869bc61a7",
      "tree": "bdfcf1b08a6274bedd29d372499626a77ac94a18",
      "parents": [
        "52860a7fb6b39537df736559a716bf8c9aa52334"
      ],
      "author": {
        "name": "Jacopo Cappellato",
        "email": "jacopo.cappellato@gmail.com",
        "time": "Wed Jul 08 11:51:28 2026 +0200"
      },
      "committer": {
        "name": "Jacopo Cappellato",
        "email": "jacopo.cappellato@gmail.com",
        "time": "Wed Jul 08 12:20:48 2026 +0200"
      },
      "message": "Improved: Clarify security assumptions regarding default configuration usage in OFBiz\n"
    },
    {
      "commit": "52860a7fb6b39537df736559a716bf8c9aa52334",
      "tree": "5054c01dde9bace08b0153185a31cffb6904f47e",
      "parents": [
        "d711a69722c9a80992c89239567dddc88f13b56a"
      ],
      "author": {
        "name": "dependabot[bot]",
        "email": "49699333+dependabot[bot]@users.noreply.github.com",
        "time": "Tue Jul 07 13:37:26 2026 +0000"
      },
      "committer": {
        "name": "Jacopo Cappellato",
        "email": "jacopo.cappellato@gmail.com",
        "time": "Wed Jul 08 10:03:25 2026 +0200"
      },
      "message": "Bump github/codeql-action/upload-sarif\n\nBumps [github/codeql-action/upload-sarif](https://github.com/github/codeql-action) from ae4c8d057d67a1b17026d584ad10186562334d21 to 006d029c8dc7b906d4ce5b7c700d32f20f2d35dd.\n- [Release notes](https://github.com/github/codeql-action/releases)\n- [Changelog](https://github.com/github/codeql-action/blob/main/CHANGELOG.md)\n- [Commits](https://github.com/github/codeql-action/compare/ae4c8d057d67a1b17026d584ad10186562334d21...006d029c8dc7b906d4ce5b7c700d32f20f2d35dd)\n\n---\nupdated-dependencies:\n- dependency-name: github/codeql-action/upload-sarif\n  dependency-version: 006d029c8dc7b906d4ce5b7c700d32f20f2d35dd\n  dependency-type: direct:production\n...\n\nSigned-off-by: dependabot[bot] \u003csupport@github.com\u003e"
    },
    {
      "commit": "d711a69722c9a80992c89239567dddc88f13b56a",
      "tree": "58f858a32cf7657a41cc50471c70a2b5ca8d86ea",
      "parents": [
        "91f49693100a78725be0d50bd1fa9c88965245b1"
      ],
      "author": {
        "name": "Divesh Dutta",
        "email": "124163540+diveshdut@users.noreply.github.com",
        "time": "Tue Jul 07 15:54:09 2026 +0530"
      },
      "committer": {
        "name": "GitHub",
        "email": "noreply@github.com",
        "time": "Tue Jul 07 15:54:09 2026 +0530"
      },
      "message": "OFBIZ-13452: Use facility shipping calendars for SALES_ORDER_SHIP MRP scheduling \n\n## Summary\n\nThis change makes purchased-item MRP backward scheduling calendar-aware\nfor the `SALES_ORDER_SHIP` path by resolving\n`ProductFacility.daysToShip` against facility-specific shipping\ncalendars instead of the global `SUPPLIER` calendar.\n\nIt also keeps supplier lead time additive for this sales-order-driven\nreplenishment path, so MRP can schedule both:\n- the seller facility\u0027s final shipping/handling leg\n- the upstream supplier replenishment lead time\n\n## What changed\n\n- preserve `ProductFacility.daysToShip` separately from supplier lead\ntime in `MrpServices`\n- pass `mrpEventTypeId`, facility shipping days, and supplier lead time\ninto `ProposedOrder.calculateStartDate(...)`\n- apply facility calendar logic only for `SALES_ORDER_SHIP`\n- resolve facility calendars through `FacilityCalendar` filtered by\n`facilityCalendarTypeId\u003d\"SHIPPING\"`\n- fall back to global `DEFAULT` `TechDataCalendar`, then to direct day\narithmetic\n- apply supplier lead time only for purchased replenishment driven by\n`SALES_ORDER_SHIP`\n- add seed data for:\n  - `FacilityCalendarType.SHIPPING`\n  - `TechDataCalendarWeek` / `TechDataCalendar` with id `SHIPPING`\n- add demo data assigning `WebStoreWarehouse` to the `SHIPPING` facility\ncalendar\n\n## Business intent\n\nFor this ticket, `ProductFacility.daysToShip` is treated as the seller\nfacility\u0027s own shipping/handling time.\n\n`SALES_ORDER_SHIP` is the downstream demand signal. When MRP needs to\npropose purchased replenishment for that demand, supplier lead time is\napplied as the upstream replenishment leg, while facility shipping time\nis applied as the final seller-controlled leg.\n\n## Scope\n\nIncluded:\n- `SALES_ORDER_SHIP` purchased-item backward scheduling\n- facility-specific shipping calendar lookup\n- additive scheduling of facility shipping time and supplier lead time\nfor this path"
    },
    {
      "commit": "91f49693100a78725be0d50bd1fa9c88965245b1",
      "tree": "5a006164d58e8e5800c7da9d4845ef19290fa91d",
      "parents": [
        "e7715d76eaf1a064621954fecb539e41d436e45f"
      ],
      "author": {
        "name": "dependabot[bot]",
        "email": "49699333+dependabot[bot]@users.noreply.github.com",
        "time": "Mon Jul 06 13:36:22 2026 +0000"
      },
      "committer": {
        "name": "Jacopo Cappellato",
        "email": "jacopo.cappellato@gmail.com",
        "time": "Mon Jul 06 16:37:31 2026 +0200"
      },
      "message": "Bump github/codeql-action/upload-sarif\n\nBumps [github/codeql-action/upload-sarif](https://github.com/github/codeql-action) from 3cf0a529d8434171b6af190714e8d5b7abb83927 to ae4c8d057d67a1b17026d584ad10186562334d21.\n- [Release notes](https://github.com/github/codeql-action/releases)\n- [Changelog](https://github.com/github/codeql-action/blob/main/CHANGELOG.md)\n- [Commits](https://github.com/github/codeql-action/compare/3cf0a529d8434171b6af190714e8d5b7abb83927...ae4c8d057d67a1b17026d584ad10186562334d21)\n\n---\nupdated-dependencies:\n- dependency-name: github/codeql-action/upload-sarif\n  dependency-version: ae4c8d057d67a1b17026d584ad10186562334d21\n  dependency-type: direct:production\n...\n\nSigned-off-by: dependabot[bot] \u003csupport@github.com\u003e"
    },
    {
      "commit": "e7715d76eaf1a064621954fecb539e41d436e45f",
      "tree": "8824d229e621bab76e478fd7d419333b30481056",
      "parents": [
        "74ca1cfb246a219c8b215c06a48fc3bedb49f1ac"
      ],
      "author": {
        "name": "dependabot[bot]",
        "email": "49699333+dependabot[bot]@users.noreply.github.com",
        "time": "Mon Jul 06 13:34:46 2026 +0000"
      },
      "committer": {
        "name": "Jacopo Cappellato",
        "email": "jacopo.cappellato@gmail.com",
        "time": "Mon Jul 06 16:24:43 2026 +0200"
      },
      "message": "Bump docker/login-action from 4.3.0 to 4.4.0\n\nBumps [docker/login-action](https://github.com/docker/login-action) from 4.3.0 to 4.4.0.\n- [Release notes](https://github.com/docker/login-action/releases)\n- [Commits](https://github.com/docker/login-action/compare/c99871dec2022cc055c062a10cc1a1310835ceb4...af1e73f918a031802d376d3c8bbc3fe56130a9b0)\n\n---\nupdated-dependencies:\n- dependency-name: docker/login-action\n  dependency-version: 4.4.0\n  dependency-type: direct:production\n  update-type: version-update:semver-minor\n...\n\nSigned-off-by: dependabot[bot] \u003csupport@github.com\u003e"
    },
    {
      "commit": "74ca1cfb246a219c8b215c06a48fc3bedb49f1ac",
      "tree": "607ac761e4a304234ffddf046434cae7a21a408e",
      "parents": [
        "499500d653e283ccd4cbcf7d5b0885a232b8eca4"
      ],
      "author": {
        "name": "Divesh Dutta",
        "email": "124163540+diveshdut@users.noreply.github.com",
        "time": "Mon Jul 06 12:28:07 2026 +0530"
      },
      "committer": {
        "name": "GitHub",
        "email": "noreply@github.com",
        "time": "Mon Jul 06 12:28:07 2026 +0530"
      },
      "message": "OFBIZ-13451: Apply supplier lead time to purchased MRP requirements \n\n## Summary\n\nThis change improves MRP scheduling for purchased items by back-scheduling `requirementStartDate` using supplier lead time when that data is maintained.\n\nPreviously, purchased requirements were effectively created with `requirementStartDate \u003d requiredByDate`, so MRP did not indicate when procurement needed to begin in order to meet the required date.\n\n## What changed\n\n- Added supplier lead time resolution for purchased-item MRP planning in `MrpServices`\n- Fetched only active `SupplierProduct` records effective for the requirement date\n- Ignored supplier rows that do not define `standardLeadTimeDays`\n- Preferred an active primary supplier (`supplierPrefOrderId \u003d 10_MAIN_SUPPL`) when lead time is available\n- If no active primary supplier with lead time exists, fell back to the active supplier with the earliest `availableFromDate`\n- Used `supplierPrefOrderId` and then `partyId` as deterministic tie-breakers\n- Used the resolved `SupplierProduct.standardLeadTimeDays` to back-schedule the purchased requirement start date from `requiredByDate`\n- Preserved current behavior when no applicable active supplier lead time is found\n- Kept `ProductFacility.daysToShip` out of the procurement fallback logic\n- Left the existing built-vs-bought decision logic unchanged\n\n## Behavior\n\nFor purchased items:\n\n- If an active supplier with defined `standardLeadTimeDays` is found, `requirementStartDate` is calculated as `requiredByDate - leadTimeDays`\n- If no applicable supplier lead time is found, `requirementStartDate` remains equal to `requiredByDate`\n\nManufactured-item routing behavior is unchanged."
    },
    {
      "commit": "499500d653e283ccd4cbcf7d5b0885a232b8eca4",
      "tree": "af8c1cd86154fd9882683571ceadb9139c6855c9",
      "parents": [
        "ecefd07628eecd70226d8ff350a4df2505e18b5d"
      ],
      "author": {
        "name": "dependabot[bot]",
        "email": "49699333+dependabot[bot]@users.noreply.github.com",
        "time": "Fri Jul 03 13:33:53 2026 +0000"
      },
      "committer": {
        "name": "Jacopo Cappellato",
        "email": "jacopo.cappellato@gmail.com",
        "time": "Fri Jul 03 18:11:24 2026 +0200"
      },
      "message": "Bump docker/build-push-action from 7.2.0 to 7.3.0\n\nBumps [docker/build-push-action](https://github.com/docker/build-push-action) from 7.2.0 to 7.3.0.\n- [Release notes](https://github.com/docker/build-push-action/releases)\n- [Commits](https://github.com/docker/build-push-action/compare/f9f3042f7e2789586610d6e8b85c8f03e5195baf...53b7df96c91f9c12dcc8a07bcb9ccacbed38856a)\n\n---\nupdated-dependencies:\n- dependency-name: docker/build-push-action\n  dependency-version: 7.3.0\n  dependency-type: direct:production\n  update-type: version-update:semver-minor\n...\n\nSigned-off-by: dependabot[bot] \u003csupport@github.com\u003e"
    },
    {
      "commit": "ecefd07628eecd70226d8ff350a4df2505e18b5d",
      "tree": "794ebd7c7a199cbea35a1d4d28bc7c35235d0c74",
      "parents": [
        "392ab3ae25e2791563b8df85e25dc70b2e3d87a7"
      ],
      "author": {
        "name": "Jacopo Cappellato",
        "email": "jacopo.cappellato@gmail.com",
        "time": "Fri Jul 03 11:05:08 2026 +0200"
      },
      "committer": {
        "name": "Jacopo Cappellato",
        "email": "jacopo.cappellato@gmail.com",
        "time": "Fri Jul 03 11:48:39 2026 +0200"
      },
      "message": "Bump github/codeql-action/analyze from 4.36.2 to 4.36.3\n"
    },
    {
      "commit": "392ab3ae25e2791563b8df85e25dc70b2e3d87a7",
      "tree": "f38b5a8a8bc0c90065da57278c2e62c860855a90",
      "parents": [
        "dae2fc2d49a38b30659fcf4d4f104bebf9c0a9f5"
      ],
      "author": {
        "name": "Jacopo Cappellato",
        "email": "jacopo.cappellato@gmail.com",
        "time": "Fri Jul 03 10:14:51 2026 +0200"
      },
      "committer": {
        "name": "Jacopo Cappellato",
        "email": "jacopo.cappellato@gmail.com",
        "time": "Fri Jul 03 11:48:39 2026 +0200"
      },
      "message": "Bump github/codeql-action/init from 4.36.2 to 4.36.3\n"
    },
    {
      "commit": "dae2fc2d49a38b30659fcf4d4f104bebf9c0a9f5",
      "tree": "2c2a686114a0a01b0ca03fbca7ef6d985af49623",
      "parents": [
        "da2d4cbceca626f54e337651c5267c9ff42e9db8"
      ],
      "author": {
        "name": "dependabot[bot]",
        "email": "49699333+dependabot[bot]@users.noreply.github.com",
        "time": "Fri Jul 03 07:20:15 2026 +0000"
      },
      "committer": {
        "name": "Jacopo Cappellato",
        "email": "jacopo.cappellato@gmail.com",
        "time": "Fri Jul 03 11:48:39 2026 +0200"
      },
      "message": "Bump github/codeql-action/autobuild from 4.36.2 to 4.36.3\n\nBumps [github/codeql-action/autobuild](https://github.com/github/codeql-action) from 4.36.2 to 4.36.3.\n- [Release notes](https://github.com/github/codeql-action/releases)\n- [Changelog](https://github.com/github/codeql-action/blob/main/CHANGELOG.md)\n- [Commits](https://github.com/github/codeql-action/compare/8aad20d150bbac5944a9f9d289da16a4b0d87c1e...54f647b7e1bb85c95cddabcd46b0c578ec92bc1a)\n\n---\nupdated-dependencies:\n- dependency-name: github/codeql-action/autobuild\n  dependency-version: 4.36.3\n  dependency-type: direct:production\n  update-type: version-update:semver-patch\n...\n\nSigned-off-by: dependabot[bot] \u003csupport@github.com\u003e"
    },
    {
      "commit": "da2d4cbceca626f54e337651c5267c9ff42e9db8",
      "tree": "9505fcb34f7bb1d8cc16c845da05bdf10917c64b",
      "parents": [
        "29a1947a51e8d8a550a1ffc2177f483c0401b6ad"
      ],
      "author": {
        "name": "dependabot[bot]",
        "email": "49699333+dependabot[bot]@users.noreply.github.com",
        "time": "Thu Jul 02 13:40:00 2026 +0000"
      },
      "committer": {
        "name": "Jacopo Cappellato",
        "email": "jacopo.cappellato@gmail.com",
        "time": "Fri Jul 03 09:18:05 2026 +0200"
      },
      "message": "Bump docker/metadata-action from 6.1.0 to 6.2.0\n\nBumps [docker/metadata-action](https://github.com/docker/metadata-action) from 6.1.0 to 6.2.0.\n- [Release notes](https://github.com/docker/metadata-action/releases)\n- [Commits](https://github.com/docker/metadata-action/compare/80c7e94dd9b9319bd5eb7a0e0fe9291e23a2a2e9...dc802804100637a589fabce1cb79ff13a1411302)\n\n---\nupdated-dependencies:\n- dependency-name: docker/metadata-action\n  dependency-version: 6.2.0\n  dependency-type: direct:production\n  update-type: version-update:semver-minor\n...\n\nSigned-off-by: dependabot[bot] \u003csupport@github.com\u003e"
    },
    {
      "commit": "29a1947a51e8d8a550a1ffc2177f483c0401b6ad",
      "tree": "d406e150fbde5e4be9b83c4a7c939821b9112c0b",
      "parents": [
        "30d98dde264edcd50280b0f7c6a26f69650a1e0c"
      ],
      "author": {
        "name": "dependabot[bot]",
        "email": "49699333+dependabot[bot]@users.noreply.github.com",
        "time": "Thu Jul 02 13:40:15 2026 +0000"
      },
      "committer": {
        "name": "Jacopo Cappellato",
        "email": "jacopo.cappellato@gmail.com",
        "time": "Fri Jul 03 09:17:29 2026 +0200"
      },
      "message": "Bump docker/login-action from 4.2.0 to 4.3.0\n\nBumps [docker/login-action](https://github.com/docker/login-action) from 4.2.0 to 4.3.0.\n- [Release notes](https://github.com/docker/login-action/releases)\n- [Commits](https://github.com/docker/login-action/compare/650006c6eb7dba73a995cc03b0b2d7f5ca915bee...c99871dec2022cc055c062a10cc1a1310835ceb4)\n\n---\nupdated-dependencies:\n- dependency-name: docker/login-action\n  dependency-version: 4.3.0\n  dependency-type: direct:production\n  update-type: version-update:semver-minor\n...\n\nSigned-off-by: dependabot[bot] \u003csupport@github.com\u003e"
    },
    {
      "commit": "30d98dde264edcd50280b0f7c6a26f69650a1e0c",
      "tree": "8a78c2e59559b0672fd8daab61db4e77dbdbc7e3",
      "parents": [
        "d9fe893119d78c1531a3a6f300513d55a9f8e8e6"
      ],
      "author": {
        "name": "dependabot[bot]",
        "email": "49699333+dependabot[bot]@users.noreply.github.com",
        "time": "Thu Jul 02 13:41:45 2026 +0000"
      },
      "committer": {
        "name": "Jacopo Cappellato",
        "email": "jacopo.cappellato@gmail.com",
        "time": "Thu Jul 02 17:07:36 2026 +0200"
      },
      "message": "Bump github/codeql-action/upload-sarif\n\nBumps [github/codeql-action/upload-sarif](https://github.com/github/codeql-action) from 9cea5827c668a1fe7165dbce6e80c3f9cf3f83ac to 3cf0a529d8434171b6af190714e8d5b7abb83927.\n- [Release notes](https://github.com/github/codeql-action/releases)\n- [Changelog](https://github.com/github/codeql-action/blob/main/CHANGELOG.md)\n- [Commits](https://github.com/github/codeql-action/compare/9cea5827c668a1fe7165dbce6e80c3f9cf3f83ac...3cf0a529d8434171b6af190714e8d5b7abb83927)\n\n---\nupdated-dependencies:\n- dependency-name: github/codeql-action/upload-sarif\n  dependency-version: 3cf0a529d8434171b6af190714e8d5b7abb83927\n  dependency-type: direct:production\n...\n\nSigned-off-by: dependabot[bot] \u003csupport@github.com\u003e"
    },
    {
      "commit": "d9fe893119d78c1531a3a6f300513d55a9f8e8e6",
      "tree": "ec41e2a8fa2b004874806623a9559a78e0b55aa3",
      "parents": [
        "eb0e569796636d10f6ce1509ed3381cb30114625"
      ],
      "author": {
        "name": "Anil K Patel",
        "email": "anil.patel@hotwax.co",
        "time": "Wed Jul 01 09:27:15 2026 -0400"
      },
      "committer": {
        "name": "GitHub",
        "email": "noreply@github.com",
        "time": "Wed Jul 01 18:57:15 2026 +0530"
      },
      "message": "Fixed: StringToTimestamp now accepts ISO 8601 timestamps (OFBIZ-2139) (#1399)\n\n## OFBIZ-2139\n\nhttps://issues.apache.org/jira/browse/OFBIZ-2139\n\n### Problem\n`StringToTimestamp.convert()` in `DateTimeConverters.java` parses with\nthe fixed\n`yyyy-MM-dd HH:mm:ss.SSS` format (space separator, no zone). ISO 8601\ntimestamps\nsuch as `2009-01-15T00:00:00.000Z` — which OFBiz\u0027s own SOAP\nserialization emits, and\nwhich REST clients and external integrations commonly send — fail the\nparse and raise\na service validation error (`Type check failed ... expected type is\n[java.sql.Timestamp];\nactual type is [java.lang.String]`). This breaks SOAP round-trips of a\nTimestamp value.\n\n### Change\nAdds an early-exit in `convert()`: when the input contains a `T`, try\n`Instant.parse(str)` first and return `Timestamp.from(...)`. If it is\nnot a valid ISO\ninstant, it falls through to the existing logic unchanged.\n\n- No impact on any existing format — only `T`-containing strings take\nthe new path, and\n  only when they parse as an ISO instant.\n- Scope note for reviewers: this covers ISO 8601 instants that carry an\nexplicit zone\n(e.g. the trailing `Z`), which is the reported case. ISO local\ndate-times without a\nzone (`...T00:00:00` with no `Z`/offset) still fall through. Happy to\nextend to\n`OffsetDateTime`/`LocalDateTime` if the community prefers full ISO 8601\ncoverage.\n\n### Testing\nVerified `2009-01-15T00:00:00.000Z` now converts, and existing\n`yyyy-MM-dd HH:mm:ss.SSS` inputs are unaffected.\n\n### Thanks:\nAdil BEN EL KHATTAB for reporting the issue and outlining the fix\noptions, @adrian-crum for the analysis ruling out changing the SOAP\noutput\nformat, @JacquesLeRoux for triaging and isolating the export\u003d\"true\" SOAP\npath, and Mike Fanning for identifying that the SOAP handler passes all\nparameters as strings."
    },
    {
      "commit": "eb0e569796636d10f6ce1509ed3381cb30114625",
      "tree": "46e983a645f91ed8e006d35847004317bf94ec6d",
      "parents": [
        "4226b606764b1ed54a3ebf80f667e43613356924"
      ],
      "author": {
        "name": "Deepak Dixit",
        "email": "deepak@apache.org",
        "time": "Wed Jul 01 12:49:29 2026 +0530"
      },
      "committer": {
        "name": "Deepak Dixit",
        "email": "deepak@apache.org",
        "time": "Wed Jul 01 12:49:29 2026 +0530"
      },
      "message": "Updated the example screen location used in ScreenFactory validation error messages to reference an existing framework screen instead of a non-existent application screen. This ensures the example is valid and avoids references to application-specific resources.(OFBIZ-13305)\n"
    },
    {
      "commit": "4226b606764b1ed54a3ebf80f667e43613356924",
      "tree": "2461f4d9eac1bd40af774816371248d9ec4cc038",
      "parents": [
        "412c6006acab2f81cd8bf2f923ff7d11dd05bad9"
      ],
      "author": {
        "name": "Deepak Dixit",
        "email": "deepak@apache.org",
        "time": "Wed Jul 01 12:39:33 2026 +0530"
      },
      "committer": {
        "name": "Deepak Dixit",
        "email": "deepak@apache.org",
        "time": "Wed Jul 01 12:39:33 2026 +0530"
      },
      "message": "Replaced the application-specific example for the optional andCondition parameter in LookupScreens.xml with a self-contained example.(OFBIZ-13305)\n"
    },
    {
      "commit": "412c6006acab2f81cd8bf2f923ff7d11dd05bad9",
      "tree": "b41ebb9caa09dd61d72f8e52a3075fda2f70dae9",
      "parents": [
        "66c7f59d998af1c920ebfdbedabd402df2963a35"
      ],
      "author": {
        "name": "Deepak Dixit",
        "email": "deepak@apache.org",
        "time": "Wed Jul 01 12:27:40 2026 +0530"
      },
      "committer": {
        "name": "Deepak Dixit",
        "email": "deepak.dixit@hotwax.co",
        "time": "Wed Jul 01 12:30:08 2026 +0530"
      },
      "message": "Moved EmailScreens.xml#ServiceNotification from application/content to framework/common (OFBIZ-13453)\n"
    },
    {
      "commit": "66c7f59d998af1c920ebfdbedabd402df2963a35",
      "tree": "0011420d0ffd7a4c51ba51ea1dc19c3c0c8f00d2",
      "parents": [
        "70157e5c4da92949b97baedc47f9645bd8667449"
      ],
      "author": {
        "name": "Deepak Dixit",
        "email": "deepak@apache.org",
        "time": "Wed Jul 01 11:39:32 2026 +0530"
      },
      "committer": {
        "name": "Deepak Dixit",
        "email": "deepak.dixit@hotwax.co",
        "time": "Wed Jul 01 11:49:54 2026 +0530"
      },
      "message": "Updated ShoppingCartEvents.destroyCart() to invoke clearCart() after removing session attributes (OFBIZ-6805)\nPreviously, clearCart() could invalidate the session for anonymous users before destroyCart() attempted to remove additional session attributes, resulting in a Session already invalidated exception.\n"
    },
    {
      "commit": "70157e5c4da92949b97baedc47f9645bd8667449",
      "tree": "2bacb3e5ca0784648f3c7f769d2b4e40e5d13bec",
      "parents": [
        "e9750fb937c7dc23774d9f304ba731172bf09a69"
      ],
      "author": {
        "name": "Deepak Dixit",
        "email": "deepak@apache.org",
        "time": "Wed Jul 01 11:13:17 2026 +0530"
      },
      "committer": {
        "name": "Deepak Dixit",
        "email": "deepak.dixit@hotwax.co",
        "time": "Wed Jul 01 11:25:51 2026 +0530"
      },
      "message": "Adjusted the indentation of the NUMERIC_FIELD_TYPES declaration to match the project’s code formatting conventions.\n"
    },
    {
      "commit": "e9750fb937c7dc23774d9f304ba731172bf09a69",
      "tree": "9ea199e36d278fc3f4fc2458cb93d8111d49f0cf",
      "parents": [
        "3eaef2fdbf3cbd6c1c7ef61e81a4789df1597fc9"
      ],
      "author": {
        "name": "Deepak Dixit",
        "email": "deepak@apache.org",
        "time": "Wed Jul 01 11:09:04 2026 +0530"
      },
      "committer": {
        "name": "Deepak Dixit",
        "email": "deepak.dixit@hotwax.co",
        "time": "Wed Jul 01 11:25:51 2026 +0530"
      },
      "message": "Replaced the mutable HashSet initialization of NUMERIC_FIELD_TYPES with Set.of(...).\n"
    },
    {
      "commit": "3eaef2fdbf3cbd6c1c7ef61e81a4789df1597fc9",
      "tree": "44696c1a11e3242a34e3894784c24508c6d12802",
      "parents": [
        "29f29853a78ba53fabf3d2d720def27cd177ba9d"
      ],
      "author": {
        "name": "Deepak Dixit",
        "email": "deepak@apache.org",
        "time": "Tue Jun 30 20:17:08 2026 +0530"
      },
      "committer": {
        "name": "Deepak Dixit",
        "email": "deepak.dixit@hotwax.co",
        "time": "Wed Jul 01 11:25:51 2026 +0530"
      },
      "message": "Fixed: ComplexAliasField default value not quoted for non-numeric fields in SQL COALESCE (OFBIZ-5199)\nThe defaultValue in ComplexAliasField.makeAliasColName() was inserted raw\ninto COALESCE SQL, causing syntax errors for date-time and string field types.\nNumeric literals (0) worked fine but timestamp/string values were unquoted.\n"
    },
    {
      "commit": "29f29853a78ba53fabf3d2d720def27cd177ba9d",
      "tree": "1ed91d92e982bfe30846f5a999fb3705a6e321ef",
      "parents": [
        "f8a94512fd0dea22b9c78e8d2883476afdb199c4"
      ],
      "author": {
        "name": "Anahita Goljahani",
        "email": "anahita.goljahani@gmail.com",
        "time": "Tue Jun 30 12:00:25 2026 +0200"
      },
      "committer": {
        "name": "Anahita Goljahani",
        "email": "anahita.goljahani@gmail.com",
        "time": "Tue Jun 30 16:38:48 2026 +0200"
      },
      "message": "Improved: Apply common label and form alignment in the Receive Inventory screen and remove unnecessary colons from labels\n"
    },
    {
      "commit": "f8a94512fd0dea22b9c78e8d2883476afdb199c4",
      "tree": "e7cdd5c5746f28bbb7e973d818b3fca8318af064",
      "parents": [
        "aba729ddcd015a319c1cd792d29811840f83456a"
      ],
      "author": {
        "name": "Anahita Goljahani",
        "email": "anahita.goljahani@gmail.com",
        "time": "Thu Jun 25 20:30:01 2026 +0200"
      },
      "committer": {
        "name": "Anahita Goljahani",
        "email": "anahita.goljahani@gmail.com",
        "time": "Tue Jun 30 16:38:48 2026 +0200"
      },
      "message": "Fixed: Replace links with submit inputs in OrderShippingInfo.ftl for the \u0027Quick Receive Purchase Order\u0027 and \u0027Receive\u0027 actions displayed when a shipment has already been created\n\nThis commit alligns the \u0027Quick Receive Purchase Order\u0027 and \u0027Receive\u0027 buttons with the corresponding dropdown menus on the order view screen and makes their style consistent with the \"Force Complete Purchase Order\" button.\n"
    },
    {
      "commit": "aba729ddcd015a319c1cd792d29811840f83456a",
      "tree": "207b8ea8b130cc7c1cc326e2d5dab2f29741df01",
      "parents": [
        "fe294798ff02eb6c1bb5fba6585fdb46ea9b755d"
      ],
      "author": {
        "name": "Anahita Goljahani",
        "email": "anahita.goljahani@gmail.com",
        "time": "Mon Jun 22 20:08:21 2026 +0200"
      },
      "committer": {
        "name": "Anahita Goljahani",
        "email": "anahita.goljahani@gmail.com",
        "time": "Tue Jun 30 16:38:48 2026 +0200"
      },
      "message": "Fixed: Correct indentation in OrderShippingInfo.ftl\n"
    },
    {
      "commit": "fe294798ff02eb6c1bb5fba6585fdb46ea9b755d",
      "tree": "3e74f61894e6a8b1d24c68418797edd455c28b63",
      "parents": [
        "17cce1c6c09ca07537185bc4b0b1e71e5229d446"
      ],
      "author": {
        "name": "Anahita Goljahani",
        "email": "anahita.goljahani@gmail.com",
        "time": "Mon Jun 22 20:06:14 2026 +0200"
      },
      "committer": {
        "name": "Anahita Goljahani",
        "email": "anahita.goljahani@gmail.com",
        "time": "Tue Jun 30 16:38:48 2026 +0200"
      },
      "message": "Fixed: Replace link with submit button for receiving purchase orders in OrderShippingInfo.ftl when a shipment has not been created yet\n\nThis commit aligns the \u0027Receive\u0027 button on the order view screen with the dropdown menu and makes its style consistent with the \u0027Quick Receive Purchase Order\u0027 button.\n"
    },
    {
      "commit": "17cce1c6c09ca07537185bc4b0b1e71e5229d446",
      "tree": "baf5b4c750189c7504e962e9bda5e873d3633fe9",
      "parents": [
        "be630727a56480a08aa9f22759f464ffd633b496"
      ],
      "author": {
        "name": "Anahita Goljahani",
        "email": "anahita.goljahani@gmail.com",
        "time": "Mon Jun 22 18:13:01 2026 +0200"
      },
      "committer": {
        "name": "Anahita Goljahani",
        "email": "anahita.goljahani@gmail.com",
        "time": "Tue Jun 30 16:38:48 2026 +0200"
      },
      "message": "Fixed: Add order type check for gift message display logic in order view screen\n\nThe commit hides gift-related information on the order view page for \u0027purchase\u0027 orders, as it is not relevant.\n"
    },
    {
      "commit": "be630727a56480a08aa9f22759f464ffd633b496",
      "tree": "32db41fcf423084333517a33c10cab6a27c3415f",
      "parents": [
        "dbbcf24368d7967a50346b97497b067151c447e2"
      ],
      "author": {
        "name": "toaditi",
        "email": "154910926+toaditi@users.noreply.github.com",
        "time": "Tue Jun 30 18:10:26 2026 +0530"
      },
      "committer": {
        "name": "GitHub",
        "email": "noreply@github.com",
        "time": "Tue Jun 30 18:10:26 2026 +0530"
      },
      "message": "Fixed: The port offset is being applied twice when loading WebSite properties (OFBIZ-13352) (#1392)\n\n**JIRA:**\n[OFBIZ-13352](https://issues.apache.org/jira/browse/OFBIZ-13352)\n\n`WebSiteProperties.from(HttpServletRequest)` delegates to\n`from(GenericValue)` when the request resolves to a `WebSite` entity.\n`from(GenericValue)` already applies the configured port offset, but the\nrequest method then applied it a **second time**, so with a non-zero\n`portOffset` the generated http and https ports were offset twice.\n\nThis builds on the approach in #949 (thanks @Lukas-Finster). #949 fixes\nthe **https** port; this change also covers the **http** port, which is\nstill offset twice there because `addPortOffset(boolean addHttpsOffset)`\noffsets the http port *unconditionally* (the flag only guards the https\npart). Rather than toggling the flag, this skips the offset call\nentirely on the WebSite-entity path (where the offset is already\napplied), and keeps a separate `addHttpsOffset` flag for the \"https port\ntaken from the request\" case.\n\n### Verification\n\nRan OFBiz with `--portoffset\u003d10000` and a `WebSite` entity present for\nthe ecommerce webapp (`webSiteId\u003dWebStore`), logging the ports\n`WebSiteProperties.from(request)` actually computes:\n\n| | httpPort | httpsPort |\n|---|---|---|\n| trunk | 28080 | 28443 |\n| #949 | 28080 | **18443** |\n| this PR | **18080** | **18443** |\n\nWith this change the secure redirect lands on\n`https://localhost:18443/…` and non-secure full-path URLs use `:18080`,\nboth matching the actual offset listeners. Behaviour is unchanged when\n`portOffset` is `0` (the default).\n\nAlso verified with `./gradlew compileJava` and `./gradlew\ncheckstyleMain`.\n\n\u003e Note for reviewers: a `WebSite` entity must exist for the affected\n`webSiteId` to reproduce this — with a seed-only DB everything falls\nback to the default path and the bug doesn\u0027t surface."
    },
    {
      "commit": "dbbcf24368d7967a50346b97497b067151c447e2",
      "tree": "5302b1eb40b59c6c1a1d32b916d9b957eb9ccda2",
      "parents": [
        "bf5e6bb4ff9b73198b657c4a0086e1592f9fbab0"
      ],
      "author": {
        "name": "Ashish Vijaywargiya",
        "email": "ashish@apache.org",
        "time": "Tue Jun 30 16:51:38 2026 +0530"
      },
      "committer": {
        "name": "GitHub",
        "email": "noreply@github.com",
        "time": "Tue Jun 30 16:51:38 2026 +0530"
      },
      "message": "Complex alias warning fix (#1391)\n\nPROBLEM STATEMENT - Fixing the console warning on every startup.\n-----------------\n\nModelViewEntity.populateReverseLinks() builds ModelConversion mappings\nthat drive the entity cache invalidation system. When a member entity\nrow changes (e.g. OrderItem), OFBiz uses these mappings to build a probe\nkey — a partial map of field→value pairs — and evicts any cached\nview-entity entries that match it.\n\nFor simple aliases, the mapping is straightforward: memberField →\nviewAliasName. For complex aliases (\u003ccomplex-alias\u003e in XML — expressions\nlike arithmetic, COALESCE, UPPER, aggregate functions like SUM/COUNT),\nno mapping was registered. The alias stayed in the wildcards set, which\nproduced EntityOperator.WILDCARD in the probe key, meaning \"match any\ncached entry regardless of this field\u0027s value.\" This was safe (never\nmissed an eviction) but overly broad (evicted entries that did not\nactually change).\n\nA Debug.logWarning() fired for every such alias on every server startup\n— noisy and not actionable.\n\n2026-06-30 15:51:23,151 |main |ContainerLoader :151|I| Starting\ncontainer delegator-container\nAdmin socket configured on - /127.0.0.1:10523\n2026-06-30 15:51:23,153 |delegator-startup-1 |DelegatorFactoryImpl\n:33|I| Creating new delegator [default] (delegator-startup-1)\n2026-06-30 15:51:23,405 |delegator-startup-1 |ModelViewEntity :674|W|\n[TestingCryptoRawView]: Conversion for complex-alias needs to be\nimplemented for cache and in-memory eval stuff to work correctly, will\nnot work for alias: rawEncryptedValue\n2026-06-30 15:51:23,405 |delegator-startup-1 |ModelViewEntity :674|W|\n[TestingCryptoRawView]: Conversion for complex-alias needs to be\nimplemented for cache and in-memory eval stuff to work correctly, will\nnot work for alias: rawSaltedEncryptedValue\n2026-06-30 15:51:23,437 |delegator-startup-1 |ModelViewEntity :674|W|\n[OrderItemQuantityReportGroupByItem]: Conversion for complex-alias needs\nto be implemented for cache and in-memory eval stuff to work correctly,\nwill not work for alias: quantityOrdered\n2026-06-30 15:51:23,437 |delegator-startup-1 |ModelViewEntity :674|W|\n[OrderItemQuantityReportGroupByItem]: Conversion for complex-alias needs\nto be implemented for cache and in-memory eval stuff to work correctly,\nwill not work for alias: quantityOpen\n2026-06-30 15:51:23,437 |delegator-startup-1 |ModelViewEntity :674|W|\n[OrderItemQuantityReportGroupByProduct]: Conversion for complex-alias\nneeds to be implemented for cache and in-memory eval stuff to work\ncorrectly, will not work for alias: quantityOrdered\n2026-06-30 15:51:23,437 |delegator-startup-1 |ModelViewEntity :674|W|\n[OrderItemQuantityReportGroupByProduct]: Conversion for complex-alias\nneeds to be implemented for cache and in-memory eval stuff to work\ncorrectly, will not work for alias: quantityOpen\n2026-06-30 15:51:23,438 |delegator-startup-1 |ModelViewEntity :674|W|\n[OrderReportSalesGroupByProduct]: Conversion for complex-alias needs to\nbe implemented for cache and in-memory eval stuff to work correctly,\nwill not work for alias: quantityOrdered\n2026-06-30 15:51:23,438 |delegator-startup-1 |ModelViewEntity :674|W|\n[OrderReportSalesGroupByProduct]: Conversion for complex-alias needs to\nbe implemented for cache and in-memory eval stuff to work correctly,\nwill not work for alias: amount\n2026-06-30 15:51:23,439 |delegator-startup-1 |ModelViewEntity :674|W|\n[OrderItemAndShipGrpInvResAndItemSum]: Conversion for complex-alias\nneeds to be implemented for cache and in-memory eval stuff to work\ncorrectly, will not work for alias: quantityOrdered\n2026-06-30 15:51:23,440 |delegator-startup-1 |ModelViewEntity :674|W|\n[OrderItemAndShipGrpInvResAndItemSum]: Conversion for complex-alias\nneeds to be implemented for cache and in-memory eval stuff to work\ncorrectly, will not work for alias: totQuantityAvailable\n2026-06-30 15:51:23,442 |delegator-startup-1 |ModelViewEntity :674|W|\n[ExampleStatusDetail]: Conversion for complex-alias needs to be\nimplemented for cache and in-memory eval stuff to work correctly, will\nnot work for alias: statusDelay\n2026-06-30 15:51:23,444 |delegator-startup-1 |ModelViewEntity :674|W|\n[ProjectPhaseTaskActualRatedHoursView]: Conversion for complex-alias\nneeds to be implemented for cache and in-memory eval stuff to work\ncorrectly, will not work for alias: totalRatedHours\n2026-06-30 15:51:23,458 |delegator-startup-1 |ModelReader :445|I|\nFinished loading entities; #Entities\u003d866 #ViewEntities\u003d322 #Fields\u003d8990\n#Relationships\u003d2993 #AutoRelationships\u003d2192\n2026-06-30 15:51:23,462 |delegator-startup-1 |GenericDelegator :239|I|\nDoing entity definition check...\n\n\nA patch was proposed that called addConversion(rawField, aliasName) for\nevery ComplexAliasField. The problem with that patch is that\nModelConversion.convert() copies the raw source field value directly\ninto the probe key, but the cache stores the computed alias value. These\ntwo values differ whenever the expression is non-trivial:\n\n- UPPER(P.firstName) → cache stores \"JOHN\", patch probes for \"john\" →\ncache entry never evicted → stale data\n- COALESCE(OI.qty, 0) → when qty is null, cache stores 0, patch probes\nfor null → stale data\n- OI.unitPrice + OI.quantity → cache stores the computed sum, patch\nprobes for just the unit price → stale data\n- SUM(OI.amount) → aggregate functions cannot be evaluated per row →\ncompletely wrong probe value\n\nThe original WILDCARD behavior is safe: it evicts more than needed. The\nproposed patch behavior is unsafe: it evicts less than needed and can\nleave wrong data in the cache with no error.\n\n\nWHAT WAS FIXED\n---------------------------------------\n\nFile:\nframework/entity/src/main/java/org/apache/ofbiz/entity/model/ModelViewEntity.java\n\nThe fix registers a conversion only for the one case where it is\nprovably correct: a ComplexAlias with exactly one ComplexAliasField\nmember that has no function and no defaultValue applied. In this case\nthe raw field value equals the computed alias value by identity, so the\nconversion is safe. All other cases — multiple members (arithmetic),\ntransforming functions (UPPER, LOWER, SUM, etc.), COALESCE with a\ndefault — remain in the wildcards set, giving the existing\nbroad-but-safe invalidation behavior.\n\nChange 1 — populateReverseLinks(): Replaced the TODO comment +\nDebug.logVerbose call with a dispatch to\nalias.getComplexAliasMember().bindAliasToConversions(alias.getName(),\nthis). The log noise is eliminated and the safe subset now participates\nin cache invalidation correctly.\n\nChange 2 — ModelAlias.getComplexAliasMember(): New accessor added to\nexpose the ComplexAliasMember so populateReverseLinks() can dispatch to\nit.\n\nChange 3 — ComplexAliasMember interface: Added void\nbindAliasToConversions(String aliasName, ModelViewEntity\nmodelViewEntity) as a new interface method, implemented by both concrete\nclasses.\n\nChange 4 — ComplexAlias.bindAliasToConversions(): Contains the safety\ngate. Delegates to the sole ComplexAliasField only when\ncomplexAliasMembers.size() \u003d\u003d 1, the sole member is a ComplexAliasField\ninstance, and sole.isPassThrough() returns true. All other cases are\nsilent no-ops, leaving the alias in wildcards.\n\nChange 5 — ComplexAliasField.isPassThrough() and\nComplexAliasField.bindAliasToConversions(): isPassThrough() returns true\nonly when entityAlias is non-empty, field is non-empty, function is\nempty, and defaultValue is empty. bindAliasToConversions() performs the\nsame getOrCreateModelConversion(entityAlias).addConversion(field,\naliasName) call that simple aliases use, and is only reachable through\nthe isPassThrough guard in ComplexAlias.\n\n\nTEST CASES\n----------\n\nFile:\nframework/entity/src/test/java/org/apache/ofbiz/entity/model/ModelViewEntityComplexAliasTests.java\n\nNo additional test infrastructure files are required. ModelConversion is\na final non-static inner class of ModelViewEntity and cannot be mocked\nwith the standard Mockito subclass mock maker. The positive test\ntherefore avoids mocking ModelConversion entirely — it stubs\ngetOrCreateModelConversion() to throw a sentinel exception, which proves\nthe dispatch was reached and the correct entityAlias was passed, without\nneeding to observe the ModelConversion internals. The addConversion()\ncall is a trivial HashMap put and does not require a dedicated assertion\nhere.\n\nThe class is declared final (public final class\nModelViewEntityComplexAliasTests) to satisfy the OFBiz checkstyle\nDesignForExtension rule on the setUp and tearDown lifecycle methods. All\ntest method names follow the OFBiz checkstyle pattern\n^[a-z][a-zA-Z0-9]*$ — camelCase, no underscores.\n\n11 tests in two groups, all passing. All three quality gates pass\ncleanly: checkstyleTest, check + javadoc, codenarcMain + codenarcTest.\n\nGroup 1 — ComplexAliasField.isPassThrough() (6 tests):\n\n  isPassThroughPlainFieldReferenceReturnsTrue\nCreates a ComplexAliasField with entityAlias\u003d\"ME\", field\u003d\"myField\", no\nfunction, no defaultValue. Asserts isPassThrough() returns true.\n\n  isPassThroughWithFunctionReturnsFalse\nCreates a ComplexAliasField with function\u003d\"upper\". Asserts\nisPassThrough() returns false. A transforming function means rawField !\u003d\ncomputedAlias.\n\n  isPassThroughWithDefaultValueReturnsFalse\nCreates a ComplexAliasField with defaultValue\u003d\"0\". Asserts\nisPassThrough() returns false. COALESCE changes the value when the field\nis null.\n\n  isPassThroughEmptyEntityAliasReturnsFalse\nCreates a ComplexAliasField with an empty entityAlias. Asserts\nisPassThrough() returns false. Cannot register a conversion without\nknowing which member entity to look up.\n\n  isPassThroughEmptyFieldReturnsFalse\nCreates a ComplexAliasField with an empty field name. Asserts\nisPassThrough() returns false.\n\n  isPassThroughLiteralValueConstantReturnsFalse\nCreates a ComplexAliasField with entityAlias\u003d\"\" and field\u003d\"\" but\nvalue\u003d\"LITERAL_VALUE\" (a SQL literal constant, not a column reference).\nAsserts isPassThrough() returns false.\n\nGroup 2 — ComplexAlias.bindAliasToConversions() safety gate (5 tests):\n\nbindAliasToConversionsSinglePassThroughFieldRegistersConversion\n[POSITIVE]\nCreates a ComplexAlias with one pass-through ComplexAliasField\n(ME.myField, no function, no default). Stubs\ngetOrCreateModelConversion() to throw a sentinel\nUnsupportedOperationException. Calls bindAliasToConversions(\"myAlias\",\nmockViewEntity) and asserts the exception is thrown, confirming the\ndispatch reached the registration code. Then verifies\ngetOrCreateModelConversion was called with entityAlias \"ME\", confirming\nthe correct member entity was targeted.\n\nbindAliasToConversionsSingleFieldWithFunctionDoesNotRegister [NEGATIVE]\nCreates a ComplexAlias with one ComplexAliasField that has\nfunction\u003d\"upper\". Calls bindAliasToConversions. Verifies\ngetOrCreateModelConversion was never called — the alias stays as a\nwildcard.\n\nbindAliasToConversionsSingleFieldWithDefaultValueDoesNotRegister\n[NEGATIVE]\nCreates a ComplexAlias with one ComplexAliasField that has\ndefaultValue\u003d\"0\". Calls bindAliasToConversions. Verifies\ngetOrCreateModelConversion was never called.\n\n  bindAliasToConversionsMultipleMembersDoesNotRegister  [NEGATIVE]\nCreates a ComplexAlias with two ComplexAliasField members (unitPrice and\nquantity, simulating an arithmetic expression like unitPrice +\nquantity). Calls bindAliasToConversions. Verifies\ngetOrCreateModelConversion was never called — the computed sum cannot be\nrepresented as a raw field value.\n\nbindAliasToConversionsNestedComplexAliasAsSoleMemberDoesNotRegister\n[NEGATIVE]\nCreates an outer ComplexAlias whose sole member is another (inner)\nComplexAlias, not a ComplexAliasField. Calls bindAliasToConversions on\nthe outer alias. Verifies getOrCreateModelConversion was never called —\nthe instanceof ComplexAliasField check in the safety gate correctly\nblocks this case."
    },
    {
      "commit": "bf5e6bb4ff9b73198b657c4a0086e1592f9fbab0",
      "tree": "ef0cd9ca93e8290805b8ca97b0bc2d4d585352d4",
      "parents": [
        "127f3cf209144e88d97d57c2f467dc42f359f4f3"
      ],
      "author": {
        "name": "Ashish Vijaywargiya",
        "email": "ashish@apache.org",
        "time": "Tue Jun 30 15:14:51 2026 +0530"
      },
      "committer": {
        "name": "GitHub",
        "email": "noreply@github.com",
        "time": "Tue Jun 30 15:14:51 2026 +0530"
      },
      "message": "Test cases fixes (#1390)\n\nFixes the following issues observed in the ./gradlew testIntegration\ncommand.\n\n1. ServiceDispatcher.java — null-guard for ctx after getLocalContext()\nprevents NPE when async SECA jobs fire after dispatcher shutdown\n\n2. ModelViewEntity.java — logWarning → logVerbose for the long-standing\nTODO about complex-alias cache conversion (repeated on every startup,\nnot actionable without major framework work)\n\n3. ServiceEcaUtil.java — logWarning → logVerbose for duplicate ECA\ndetection (false positives from concurrent dispatcher initialization\nduring tests)\n\n4. applications/product/servicedef/services.xml — removed invalid\naction\u003d\"GET\" attribute from \u003cservice\u003e element\n\n5. framework/service/testdef/servicetests.xml — removed\nname\u003d\"engine-tracker\" from \u003cjunit-test-suite\u003e (not in schema)\n\n6. applications/order/servicedef/services_quote.xml — merged two\nduplicate createQuoteWorkEffort definitions into one (eliminating the\n\"defined more than once\" warning)\n\n7. MiscUelTest.groovy — fixed ${sys:getenv} and ${sys:getProperty} to\nuse proper EL function call syntax with arguments, eliminating ERROR log\nentries from FlexibleStringExpander"
    },
    {
      "commit": "127f3cf209144e88d97d57c2f467dc42f359f4f3",
      "tree": "421157db6fa24453e597ef4e94446ea3102859c2",
      "parents": [
        "16f410491405e901659bff1638a2a9c0a638b525"
      ],
      "author": {
        "name": "Jacopo Cappellato",
        "email": "jacopo.cappellato@gmail.com",
        "time": "Mon Jun 29 16:26:08 2026 +0200"
      },
      "committer": {
        "name": "Jacopo Cappellato",
        "email": "jacopo.cappellato@gmail.com",
        "time": "Mon Jun 29 16:51:05 2026 +0200"
      },
      "message": "Improved: Simplify handling of hidden fields in order search form\n"
    },
    {
      "commit": "16f410491405e901659bff1638a2a9c0a638b525",
      "tree": "3f392d7a88fab8b400473c7eef0d06608ad2220d",
      "parents": [
        "542433de40fc364b1cc0849764fc5d77e3bea528"
      ],
      "author": {
        "name": "Ashish Vijaywargiya",
        "email": "ashish@apache.org",
        "time": "Sat Jun 27 18:47:49 2026 +0530"
      },
      "committer": {
        "name": "GitHub",
        "email": "noreply@github.com",
        "time": "Sat Jun 27 18:47:49 2026 +0530"
      },
      "message": "Re organise entityengine content (#1386)\n\nReorganised the entityengine.xml contents a bit. No functional changes."
    },
    {
      "commit": "542433de40fc364b1cc0849764fc5d77e3bea528",
      "tree": "86965598e35662c08673a9063407690ce8d4372d",
      "parents": [
        "b682ad4ff3856b4af9f8c9a5a6a17144a808c8b1"
      ],
      "author": {
        "name": "dependabot[bot]",
        "email": "49699333+dependabot[bot]@users.noreply.github.com",
        "time": "Fri Jun 26 13:33:46 2026 +0000"
      },
      "committer": {
        "name": "Jacopo Cappellato",
        "email": "jacopo.cappellato@gmail.com",
        "time": "Fri Jun 26 18:12:54 2026 +0200"
      },
      "message": "Bump org.apache.tomcat:tomcat-jasper from 10.1.55 to 10.1.56\n\nBumps org.apache.tomcat:tomcat-jasper from 10.1.55 to 10.1.56.\n\n---\nupdated-dependencies:\n- dependency-name: org.apache.tomcat:tomcat-jasper\n  dependency-version: 10.1.56\n  dependency-type: direct:production\n  update-type: version-update:semver-patch\n...\n\nSigned-off-by: dependabot[bot] \u003csupport@github.com\u003e"
    },
    {
      "commit": "b682ad4ff3856b4af9f8c9a5a6a17144a808c8b1",
      "tree": "75848d883b589517cc43189409846c81b798415a",
      "parents": [
        "865b7aa38857324edaae306ff779673cce05dc2f"
      ],
      "author": {
        "name": "dependabot[bot]",
        "email": "49699333+dependabot[bot]@users.noreply.github.com",
        "time": "Fri Jun 26 13:35:07 2026 +0000"
      },
      "committer": {
        "name": "Jacopo Cappellato",
        "email": "jacopo.cappellato@gmail.com",
        "time": "Fri Jun 26 17:56:45 2026 +0200"
      },
      "message": "Bump github/codeql-action/upload-sarif\n\nBumps [github/codeql-action/upload-sarif](https://github.com/github/codeql-action) from 9fc351a8ac7432cff4cf6b2e45db91873bec9bf9 to 9cea5827c668a1fe7165dbce6e80c3f9cf3f83ac.\n- [Release notes](https://github.com/github/codeql-action/releases)\n- [Changelog](https://github.com/github/codeql-action/blob/main/CHANGELOG.md)\n- [Commits](https://github.com/github/codeql-action/compare/9fc351a8ac7432cff4cf6b2e45db91873bec9bf9...9cea5827c668a1fe7165dbce6e80c3f9cf3f83ac)\n\n---\nupdated-dependencies:\n- dependency-name: github/codeql-action/upload-sarif\n  dependency-version: 9cea5827c668a1fe7165dbce6e80c3f9cf3f83ac\n  dependency-type: direct:production\n...\n\nSigned-off-by: dependabot[bot] \u003csupport@github.com\u003e"
    },
    {
      "commit": "865b7aa38857324edaae306ff779673cce05dc2f",
      "tree": "09a8f523f3623f83fca6faf35df2b02fcbfb6a22",
      "parents": [
        "a07c838c9934ad2b221360a152b12de24527a82e"
      ],
      "author": {
        "name": "dependabot[bot]",
        "email": "49699333+dependabot[bot]@users.noreply.github.com",
        "time": "Fri Jun 26 13:35:15 2026 +0000"
      },
      "committer": {
        "name": "Jacopo Cappellato",
        "email": "jacopo.cappellato@gmail.com",
        "time": "Fri Jun 26 17:40:09 2026 +0200"
      },
      "message": "Bump actions/setup-java from 5.3.0 to 5.4.0\n\nBumps [actions/setup-java](https://github.com/actions/setup-java) from 5.3.0 to 5.4.0.\n- [Release notes](https://github.com/actions/setup-java/releases)\n- [Commits](https://github.com/actions/setup-java/compare/ad2b38190b15e4d6bdf0c97fb4fca8412226d287...1bcf9fb12cf4aa7d266a90ae39939e61372fe520)\n\n---\nupdated-dependencies:\n- dependency-name: actions/setup-java\n  dependency-version: 5.4.0\n  dependency-type: direct:production\n  update-type: version-update:semver-minor\n...\n\nSigned-off-by: dependabot[bot] \u003csupport@github.com\u003e"
    },
    {
      "commit": "a07c838c9934ad2b221360a152b12de24527a82e",
      "tree": "f1c7984fa5675a5d18a1507a341ed811ef9b7ccd",
      "parents": [
        "672b6d02e6776ad5875d1a7b95c7e4764a73e3e0"
      ],
      "author": {
        "name": "Mridul Pathak",
        "email": "mridul.72@gmail.com",
        "time": "Fri Jun 26 19:24:08 2026 +0530"
      },
      "committer": {
        "name": "GitHub",
        "email": "noreply@github.com",
        "time": "Fri Jun 26 19:24:08 2026 +0530"
      },
      "message": "Improved: Remove defunct Taxware and deprecated ZIPsales™ tax integrations (OFBIZ-7936) (#1380)\n\nImproved: Remove defunct Taxware and deprecated ZIPsales™ tax\nintegrations (OFBIZ-7936)\n\nOFBiz currently ships with two third-party tax integrations — Taxware\nand ZIPsales™ — both of which are no longer functional due to the\ndiscontinuation of their underlying data providers. This PR removes all\nrelated artifacts including Java source files, MiniLang descriptors,\nservice definitions, entity definitions, configuration files, and UI\nlabels."
    },
    {
      "commit": "672b6d02e6776ad5875d1a7b95c7e4764a73e3e0",
      "tree": "01d301c3636d492a940c223a5d30dab409b61d56",
      "parents": [
        "d278d49b930d450f965433407d1c4dd4eb54d00f"
      ],
      "author": {
        "name": "Mridul Pathak",
        "email": "mridul.72@gmail.com",
        "time": "Fri Jun 26 16:13:18 2026 +0530"
      },
      "committer": {
        "name": "GitHub",
        "email": "noreply@github.com",
        "time": "Fri Jun 26 16:13:18 2026 +0530"
      },
      "message": "Fixed: Remove leftover carrier-specific shipping gateway configuration code (OFBIZ-13447) (#1377)\n\nFixed: Remove leftover carrier-specific shipping gateway configuration\ncode\n(OFBIZ-13447)\n\nAfter PR #1335 removed the DHL, FedEx, UPS, and USPS Java carrier\nintegrations, carrier-specific entity definitions, services, UI forms,\nscreens, controller mappings, seed data, and UI labels remained. This\ncommit removes all of them while preserving the generic\nShipmentGatewayConfig and ShipmentGatewayConfigType infrastructure."
    },
    {
      "commit": "d278d49b930d450f965433407d1c4dd4eb54d00f",
      "tree": "57aca8fda6bf4c648e2cebf16d75c938f5bdc59f",
      "parents": [
        "371d00ba250e1b58a72a5771739698d6bbaff3cf"
      ],
      "author": {
        "name": "Mridul Pathak",
        "email": "mridul.pathak@hotwaxsystems.com",
        "time": "Tue Jun 23 12:40:33 2026 +0530"
      },
      "committer": {
        "name": "Mridul Pathak",
        "email": "mridul.72@gmail.com",
        "time": "Fri Jun 26 15:55:46 2026 +0530"
      },
      "message": "Remove deprecated and defunct third-party payment gateway integrations and their references (OFBIZ-13446)\n"
    },
    {
      "commit": "371d00ba250e1b58a72a5771739698d6bbaff3cf",
      "tree": "0be3f225f9de1597b8f785093d41aea6208767eb",
      "parents": [
        "1ec71e080d99e00271c1ff402b7d443e407db9af"
      ],
      "author": {
        "name": "Mridul Pathak",
        "email": "mridul.pathak@hotwaxsystems.com",
        "time": "Tue Jun 23 17:08:56 2026 +0530"
      },
      "committer": {
        "name": "Mridul Pathak",
        "email": "mridul.72@gmail.com",
        "time": "Fri Jun 26 15:45:12 2026 +0530"
      },
      "message": "Fixed: Remove leftover references from deleted shipping carrier integrations (OFBIZ-7935)\n\nFollow-up cleanup after PR #1335 removed DHL, FedEx, UPS, and USPS shipping\ncarrier integrations. Removes:\n- Orphaned \u003c/#if\u003e in ReturnLinks.ftl caused by incomplete UPS block removal\n- Stale UPS comment in OrderView.groovy\n- Stale TODO comments referencing UPS/FedEx in OrderShippingInfo.ftl\n  and OrderHeaderInfo.ftl\n"
    },
    {
      "commit": "1ec71e080d99e00271c1ff402b7d443e407db9af",
      "tree": "08873dd866d47abea5c9c0e39d67c22c99f67043",
      "parents": [
        "bc15fc110417540a556331bdd0986a6733802527"
      ],
      "author": {
        "name": "dependabot[bot]",
        "email": "49699333+dependabot[bot]@users.noreply.github.com",
        "time": "Thu Jun 25 13:40:24 2026 +0000"
      },
      "committer": {
        "name": "Jacopo Cappellato",
        "email": "jacopo.cappellato@gmail.com",
        "time": "Thu Jun 25 18:14:02 2026 +0200"
      },
      "message": "Bump org.apache.tika:tika-parser-pdf-module from 3.3.0 to 3.3.1\n\nBumps org.apache.tika:tika-parser-pdf-module from 3.3.0 to 3.3.1.\n\n---\nupdated-dependencies:\n- dependency-name: org.apache.tika:tika-parser-pdf-module\n  dependency-version: 3.3.1\n  dependency-type: direct:production\n  update-type: version-update:semver-patch\n...\n\nSigned-off-by: dependabot[bot] \u003csupport@github.com\u003e"
    },
    {
      "commit": "bc15fc110417540a556331bdd0986a6733802527",
      "tree": "b4d91ccc9538e2ff7b7c19bbb7a336e0fb88a962",
      "parents": [
        "38a726ce2b89c47d5bac0ed79f585fd1f2cf09df"
      ],
      "author": {
        "name": "Anahita Goljahani",
        "email": "anahita.goljahani@gmail.com",
        "time": "Wed Jun 24 16:43:19 2026 +0200"
      },
      "committer": {
        "name": "Anahita Goljahani",
        "email": "anahita.goljahani@gmail.com",
        "time": "Wed Jun 24 16:56:28 2026 +0200"
      },
      "message": "Fixed: Add missing license header\n\nAdded a license header to address the \"Unapproved Licenses\" issue reported in the RAT report.\n"
    },
    {
      "commit": "38a726ce2b89c47d5bac0ed79f585fd1f2cf09df",
      "tree": "06e2b053c8d25afc045e6061bed3d7ab500a459f",
      "parents": [
        "dbdce61c6b57c9ac3a9cfef1b3b78bb47326507b"
      ],
      "author": {
        "name": "dependabot[bot]",
        "email": "49699333+dependabot[bot]@users.noreply.github.com",
        "time": "Tue Jun 23 13:36:53 2026 +0000"
      },
      "committer": {
        "name": "Jacopo Cappellato",
        "email": "jacopo.cappellato@gmail.com",
        "time": "Wed Jun 24 16:45:13 2026 +0200"
      },
      "message": "Bump org.mustangproject:library from 2.22.0 to 2.24.0\n\nBumps [org.mustangproject:library](https://github.com/ZUGFeRD/mustangproject) from 2.22.0 to 2.24.0.\n- [Release notes](https://github.com/ZUGFeRD/mustangproject/releases)\n- [Changelog](https://github.com/ZUGFeRD/mustangproject/blob/master/History.md)\n- [Commits](https://github.com/ZUGFeRD/mustangproject/compare/core-2.22.0...core-2.24.0)\n\n---\nupdated-dependencies:\n- dependency-name: org.mustangproject:library\n  dependency-version: 2.24.0\n  dependency-type: direct:production\n  update-type: version-update:semver-minor\n...\n\nSigned-off-by: dependabot[bot] \u003csupport@github.com\u003e"
    },
    {
      "commit": "dbdce61c6b57c9ac3a9cfef1b3b78bb47326507b",
      "tree": "a9e10bf118962cd9749c923efbace2df820b80be",
      "parents": [
        "3d30321ed0367a9e5e4ff976eb9bbfbf3f806cef"
      ],
      "author": {
        "name": "Anahita Goljahani",
        "email": "anahita.goljahani@gmail.com",
        "time": "Tue Jun 23 13:04:03 2026 +0200"
      },
      "committer": {
        "name": "Anahita Goljahani",
        "email": "anahita.goljahani@gmail.com",
        "time": "Tue Jun 23 16:06:00 2026 +0200"
      },
      "message": "Fixed: Add missing license headers\n\nThis commit fixes some of the \"unapproved licenses\" issues reported in the RAT report.\n"
    },
    {
      "commit": "3d30321ed0367a9e5e4ff976eb9bbfbf3f806cef",
      "tree": "5461b805fb1f6189996bd84daddb35cc50b70460",
      "parents": [
        "cee34a9f304b53efa12a2f08d8e549c7a18a1899"
      ],
      "author": {
        "name": "Jacopo Cappellato",
        "email": "jacopo.cappellato@gmail.com",
        "time": "Tue Jun 23 15:15:19 2026 +0200"
      },
      "committer": {
        "name": "Jacopo Cappellato",
        "email": "jacopo.cappellato@gmail.com",
        "time": "Tue Jun 23 15:33:35 2026 +0200"
      },
      "message": "Improved: Update js-yaml to version 4.2.0 to resolve a security warning\n"
    },
    {
      "commit": "cee34a9f304b53efa12a2f08d8e549c7a18a1899",
      "tree": "45cbfba5daada2efe4dd91f3b10dee624a2ecc2c",
      "parents": [
        "952990894eaf518aeabbc528b004fa6e949a352d"
      ],
      "author": {
        "name": "Jacopo Cappellato",
        "email": "jacopo.cappellato@gmail.com",
        "time": "Tue Jun 23 13:15:37 2026 +0200"
      },
      "committer": {
        "name": "Jacopo Cappellato",
        "email": "jacopo.cappellato@gmail.com",
        "time": "Tue Jun 23 15:33:35 2026 +0200"
      },
      "message": "Improved: Add daily update schedule for npm dependencies in the framework/rest-api directory\n"
    },
    {
      "commit": "952990894eaf518aeabbc528b004fa6e949a352d",
      "tree": "7259e222b659ea851e134243549d57fb5188070c",
      "parents": [
        "bba45f7abc3ab9d5ec1aa498762a783dd2fe5600"
      ],
      "author": {
        "name": "Jacopo Cappellato",
        "email": "jacopo.cappellato@gmail.com",
        "time": "Tue Jun 23 12:48:18 2026 +0200"
      },
      "committer": {
        "name": "Jacopo Cappellato",
        "email": "jacopo.cappellato@gmail.com",
        "time": "Tue Jun 23 15:33:35 2026 +0200"
      },
      "message": "Improved: Mark deprecated methods and suppress deprecation warnings in ApiContextListener, OFBizOpenApiReader, and OpenApiUtil\n"
    },
    {
      "commit": "bba45f7abc3ab9d5ec1aa498762a783dd2fe5600",
      "tree": "07dfed4a52d6846d2641c951cfa780764d99dfae",
      "parents": [
        "4af1641172843b0032e0bdbf6beb23eed27e5a62"
      ],
      "author": {
        "name": "Jacopo Cappellato",
        "email": "jacopo.cappellato@gmail.com",
        "time": "Tue Jun 23 11:48:40 2026 +0200"
      },
      "committer": {
        "name": "Jacopo Cappellato",
        "email": "jacopo.cappellato@gmail.com",
        "time": "Tue Jun 23 15:33:35 2026 +0200"
      },
      "message": "Fixed: Correct the file path for the favicon-16x16.png in swagger-ui.html\n"
    },
    {
      "commit": "4af1641172843b0032e0bdbf6beb23eed27e5a62",
      "tree": "01b12ee5efbc1fc608b4766368b838da2b61cdb8",
      "parents": [
        "83b89bb518fba4d5e6004ce3f968dbf4e4438a20"
      ],
      "author": {
        "name": "Jacopo Cappellato",
        "email": "jacopo.cappellato@gmail.com",
        "time": "Tue Jun 23 11:48:17 2026 +0200"
      },
      "committer": {
        "name": "Jacopo Cappellato",
        "email": "jacopo.cappellato@gmail.com",
        "time": "Tue Jun 23 15:33:35 2026 +0200"
      },
      "message": "Improved: Replace committed binaries in rest-api with npm-declared dependencies that are downloaded and copied into place at build time\n\nframework/rest-api/webapp/docs/ contained manually committed JavaScript, CSS, and source-map files copied verbatim from two external projects.\nThese files bloated the git history and drifted from upstream security patches.\n"
    },
    {
      "commit": "83b89bb518fba4d5e6004ce3f968dbf4e4438a20",
      "tree": "18768ff66b08e8d29d33f22531e5e70e25f2f4fc",
      "parents": [
        "4fb03d40d1c38ba6eeb5f8bcead50db224203347"
      ],
      "author": {
        "name": "Nicolas Malin",
        "email": "nicolas.malin@nereide.fr",
        "time": "Tue Jun 23 15:03:18 2026 +0200"
      },
      "committer": {
        "name": "GitHub",
        "email": "noreply@github.com",
        "time": "Tue Jun 23 15:03:18 2026 +0200"
      },
      "message": "Fixed: Fix FindGeneric on view entity (#1375)\n\nWhen you display a ViewEntity that not contains group by or function,\nthe EntityQuery failed to resolve selected fields I introduced this\nregression after a groovy reformat (adefd159d2) where this empty case\nwould not well manage"
    },
    {
      "commit": "4fb03d40d1c38ba6eeb5f8bcead50db224203347",
      "tree": "aa70e21c42e12acd56b8428c5dfaffe8c83b146d",
      "parents": [
        "a595a5c598ffde2738196dbe9da8658b62dc88fa"
      ],
      "author": {
        "name": "Deepak Dixit",
        "email": "deepak@apache.org",
        "time": "Tue Jun 16 12:09:15 2026 +0530"
      },
      "committer": {
        "name": "Deepak Dixit",
        "email": "deepak.dixit@hotwax.co",
        "time": "Tue Jun 23 15:07:10 2026 +0530"
      },
      "message": "Reverted the service definition verb attribute introduced by OFBIZ-11328 for mapping exported services to specific HTTP methods.\n\n- Exported services are currently exposed through the service engine and have historically been available via POST requests.\n- Introducing HTTP method definitions in service descriptors adds REST-specific concerns to service definitions.\n- The framework\u0027s REST implementation already provides a dedicated mechanism for defining REST endpoints through rest.xml.\n- Service definitions should remain transport-agnostic and not require HTTP method metadata.\n- Mixing service contracts and REST endpoint definitions creates duplication and can lead to inconsistent API behavior.\n\n- Remove the action attribute from service definitions.\n- Remove HTTP method mapping logic introduced for exported services.\n\nApplications requiring REST-style endpoint definitions should use rest.xml and the REST framework rather than annotating service definitions with HTTP-specific metadata.\nThis keeps service definitions independent of protocol concerns and preserves backward compatibility with existing exported service behavior.\n"
    },
    {
      "commit": "a595a5c598ffde2738196dbe9da8658b62dc88fa",
      "tree": "23d3d4a375744abe3f3c8e621029c87d2ea984e5",
      "parents": [
        "56c777a7cff93356d3e7348ed3d81fcb5ae15395"
      ],
      "author": {
        "name": "dependabot[bot]",
        "email": "49699333+dependabot[bot]@users.noreply.github.com",
        "time": "Fri Jun 19 13:33:34 2026 +0000"
      },
      "committer": {
        "name": "Jacopo Cappellato",
        "email": "jacopo.cappellato@gmail.com",
        "time": "Mon Jun 22 10:08:47 2026 +0200"
      },
      "message": "Bump actions/checkout from 6.0.3 to 7.0.0\n\nBumps [actions/checkout](https://github.com/actions/checkout) from 6.0.3 to 7.0.0.\n- [Release notes](https://github.com/actions/checkout/releases)\n- [Changelog](https://github.com/actions/checkout/blob/main/CHANGELOG.md)\n- [Commits](https://github.com/actions/checkout/compare/df4cb1c069e1874edd31b4311f1884172cec0e10...9c091bb21b7c1c1d1991bb908d89e4e9dddfe3e0)\n\n---\nupdated-dependencies:\n- dependency-name: actions/checkout\n  dependency-version: 7.0.0\n  dependency-type: direct:production\n  update-type: version-update:semver-major\n...\n\nSigned-off-by: dependabot[bot] \u003csupport@github.com\u003e"
    },
    {
      "commit": "56c777a7cff93356d3e7348ed3d81fcb5ae15395",
      "tree": "a2a8a94c7fd22cd4ab812685e83c7289d31d2b19",
      "parents": [
        "5a40cc1ee053a3fb9155b4473f9436a704f2fd3f"
      ],
      "author": {
        "name": "Jacques Le Roux",
        "email": "jacques.le.roux@les7arts.com",
        "time": "Fri Jun 19 17:29:17 2026 +0200"
      },
      "committer": {
        "name": "Jacques Le Roux",
        "email": "jacques.le.roux@les7arts.com",
        "time": "Fri Jun 19 17:29:41 2026 +0200"
      },
      "message": "Improved: trivial change in a comment\n\nChanges from\nhttps://svn.apache.org/repos/infra/infrastructure/buildbot2/projects/ofbiz.py\nto\nhttps://github.com/apache/infrastructure-bb2/blob/master/ofbiz.py\n\nAlso removes several end spaces (Eclipse automation).\n"
    },
    {
      "commit": "5a40cc1ee053a3fb9155b4473f9436a704f2fd3f",
      "tree": "eef2177de7e1bc16ef306849b37c8300df88f213",
      "parents": [
        "0b9cbae4cb808453971ec9bb3163579b1eb09599"
      ],
      "author": {
        "name": "toaditi",
        "email": "aditi.patel@hotwax.co",
        "time": "Mon Jun 15 16:57:44 2026 +0530"
      },
      "committer": {
        "name": "Mridul Pathak",
        "email": "mridul.72@gmail.com",
        "time": "Fri Jun 19 19:29:24 2026 +0530"
      },
      "message": "OFBIZ-13402 Move test sources from src/main/groovy to src/test/groovy\n\nMove 52 Groovy test files from src/main/groovy to src/test/groovy across\nall active components to prevent test code from being compiled into\nproduction JAR files and included in release artifacts.\n\nUpdate build.gradle so the OFBiz integration test runner (ofbiz --test)\nincludes the test source set classpath alongside the main classpath,\nensuring relocated test classes remain discoverable at test runtime.\n\nAlso add src/test/groovy to the createPlugin directory scaffold so new\nplugins get the correct layout from the start.\n\nNote: framework/service TestServices.groovy is intentionally NOT moved\nas it is a service implementation, not a test class.\n"
    }
  ],
  "next": "0b9cbae4cb808453971ec9bb3163579b1eb09599"
}
