Skip to content

MINOR: Bump com.squareup.okio:okio-jvm from 3.17.0 to 3.18.2 - #1295

Merged
jbonofre merged 1 commit into
mainfrom
dependabot/maven/com.squareup.okio-okio-jvm-3.18.2
Oct 3, 2026
Merged

jbonofre merged 1 commit into
mainfrom
dependabot/maven/com.squareup.okio-okio-jvm-3.18.2

Conversation

@dependabot

@dependabot dependabot Bot commented on behalf of github Sep 14, 2026 •

Copy link
Copy Markdown
Contributor

Bumps com.squareup.okio:okio-jvm from 3.17.0 to 3.18.2.

Changelog

Sourced from com.squareup.okio:okio-jvm's changelog.

Version 3.18.2

2026-09-04

  • Fix: Don't change behavior of base64-encoding. We introduced a bug in Okio 3.18.1 that caused base64 strings to be encoded without padding, even though the previous and expected behavior is to encode such strings with padding (= characters). The bug impacts callers who compiled against Okio releases < 3.18.0, and executed on Okio releases >= 3.18.

Version 3.18.1

2026-07-28

  • Fix: Restore binary-compatibility with Okio 3.17.x for Kotlin/Native users. When we introduced the new base64() function, we inadvertently changed the binary signature! Ugh! This is now fixed and we've automated binary-compatibility checking for Kotlin/Native going forward.

Version 3.18.0

2026-07-21

  • Fix: Use wide character APIs to better support of non-UTF-8 filesystems on Windows.
  • Fix: Don't crash in AssetFileSystem.exists() when the underlying storage throws a FileNotFoundException.
  • Fix: Load WASI paths relative to their preopen. The platform behavior recently changed in NodeJS, causing our WasiFileSystem to be unable to access files!
  • New: Optionally ignore whitespace when decoding hexadecimal.
  • New: Optionally omit padding when encoding Base64.
  • New: BufferedSource.readUInt(), BufferedSink.writeUInt(), and similar functions for UByte, UShort and ULong. Also add support for unsigned and little-endian.
  • New: BufferedSink.utf8Appendable(). Use this to adapt an Okio sink to an Appendable.
  • New: Source.limit() returns a wrapped source with a strict limit on how many bytes are returned.
  • New: ByteString.equals(other, constantTime) for subtle defense against timing attacks.
Commits
  • 9403a09 Prepare for release 3.18.2.
  • 5a1c153 Fix an unintended behavior change with base64 padding (#1869)
  • 9f564fd Prepare for release 3.18.1.
  • 531cf07 Hide some accidentally public symbols (#1839)
  • e7ef43d Update GitHub Actions for new secrets and branch (#1840)
  • a6730de Start enforcing binary compatibility for Kotlin/Native (#1838)
  • e75a7e9 Update dependency com.android.tools.build:gradle to v9.3.1 (#1836)
  • 9d21d5c Fix interchanged docs links for 1.x and 2.x API (#1835)
  • bff1dff Track new docs locations from Dokka v2 (#1833)
  • 3b16d9b Grant write permission to the publish-website action (#1832)
  • Additional commits viewable in compare view

@dependabot dependabot Bot added dependencies Pull requests that update a dependency file java Pull requests that update Java code labels Sep 14, 2026
@dependabot dependabot Bot added dependencies Pull requests that update a dependency file java Pull requests that update Java code labels Sep 14, 2026
@jbonofre

jbonofre commented Oct 2, 2026

Copy link
Copy Markdown
Member

@dependabot rebase

Bumps [com.squareup.okio:okio-jvm](https://github.com/lysine-dev/okio) from 3.17.0 to 3.18.2.
- [Changelog](https://github.com/lysine-dev/okio/blob/main/CHANGELOG.md)
- [Commits](lysine-dev/okio@parent-3.17.0...parent-3.18.2)

---
updated-dependencies:
- dependency-name: com.squareup.okio:okio-jvm
  dependency-version: 3.18.2
  dependency-type: direct:development
  update-type: version-update:semver-minor
...

Signed-off-by: dependabot[bot] <support@github.com>
@dependabot
dependabot Bot force-pushed the dependabot/maven/com.squareup.okio-okio-jvm-3.18.2 branch from d51e65b to 75da0fc Compare October 2, 2026 15:24
@github-actions github-actions Bot added this to the 20.0.0 milestone Oct 3, 2026
@jbonofre
jbonofre merged commit 70b149d into main Oct 3, 2026
22 of 24 checks passed
@jbonofre
jbonofre deleted the dependabot/maven/com.squareup.okio-okio-jvm-3.18.2 branch October 3, 2026 13:03
jbonofre added a commit that referenced this pull request Oct 4, 2026
## What's Changed

The `Dev PR` workflow runs on `pull_request_target`, where `github.ref`
is the base branch (`refs/heads/main`), not the PR ref. Its concurrency
group therefore resolved to `apache/arrow-java-refs/heads/main-Dev PR`
for every PR, and with `cancel-in-progress: true` a new run on one PR
cancelled the run in progress on another.

This leaves a cancelled "Ensure PR format" check on the losing PR, which
shows up as a failure. For example on #1295 the job was cancelled with:

```
Canceling since a higher priority waiting request for apache/arrow-java-refs/heads/main-Dev PR exists
```

This change keys the concurrency group on the PR number, so runs are
only cancelled by newer runs of the same PR.

Note that `pull_request_target` uses the workflow from the base branch,
so this only takes effect once merged.
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

dependencies Pull requests that update a dependency file java Pull requests that update Java code

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant