Skip to content

Update dependency org.mariadb.jdbc:mariadb-java-client to v3.5.10 - #709

Merged
AB-xdev merged 1 commit into
developfrom
renovate/org.mariadb.jdbc-mariadb-java-client-3.x
Aug 10, 2026
Merged

Update dependency org.mariadb.jdbc:mariadb-java-client to v3.5.10#709
AB-xdev merged 1 commit into
developfrom
renovate/org.mariadb.jdbc-mariadb-java-client-3.x

Conversation

@xdev-renovate

@xdev-renovate xdev-renovate commented Jul 30, 2026

Copy link
Copy Markdown
Member

This PR contains the following updates:

Package Type Update Change
org.mariadb.jdbc:mariadb-java-client (source) compile patch 3.5.93.5.10

Release Notes

mariadb-corporation/mariadb-connector-j (org.mariadb.jdbc:mariadb-java-client)

v3.5.10

Compare Source

Full Changelog

Key Enhancements
  • CONJ-1333 - Add maxAllowedPacket connection option (send/receive limit)
  • CONJ-1339 - Add maxAllowedColumns option to bound server-announced column count (report by fg0x0)
  • CONJ-1330 - add infer test to CI
Issues Resolved
  • CONJ-1332 - Reject multipart (>16 MB) packets before authentication to prevent pre-auth OOM from a rogue server
  • CONJ-1342 - socketFactory option allows loading arbitrary bytecode via jar: URL, enabling RCE when JDBC URL is
    attacker-controlled (report by Qing Xu)
  • CONJ-1307 - Connection.setReadOnly(true) still allows DML statements to execute
  • CONJ-1326 - Unsafe escaping in enquoteLiteral()/enquoteNCharLiteral() (thanks to jmestwa-coder)
  • CONJ-1327 - Align SSL hostname verification with TLS libraries (thanks to jmestwa-coder)
  • CONJ-1329 - LOAD DATA LOCAL INFILE validation fails open when a bound parameter can't be rendered (thanks to
    jmestwa-coder)
  • CONJ-1331 - trustStore-configured TLS connections defer certificate-chain/identity validation instead of validating
    up front (thanks to jmestwa-coder)
  • CONJ-1340 - SQL injection via unescaped identifiers in updatable ResultSet generated statements (thanks to
    jmestwa-coder)
  • CONJ-1341 - MariaDbPoolDataSource.getConnection(user, password) ignores the user argument when the pool's own
    password is supplied (report by fg0x0)
  • CONJ-1328 - restrictedAuth allowlist is matched with substring contains() instead of equality (thanks to
    jmestwa-coder)
  • CONJ-1338 - Validate length-encoded integers fit a non-negative int before use as a length (report by fg0x0)
  • CONJ-1336 - CONJ-1282 regression: TLS connection fails when JDBC hostname is an absolute FQDN ending with a trailing
    dot (report by Shaswata, thanks to Pepo48 for PR)
  • CONJ-1335 - getGeneratedKeys() throws "integer overflow" after a batch insert when the auto-increment value exceeds
    Integer.MAX_VALUE, and returns bulk generated keys out of batch order

Configuration

📅 Schedule: (UTC)

  • Branch creation
    • At any time (no schedule defined)
  • Automerge
    • At any time (no schedule defined)

🚦 Automerge: Disabled by config. Please merge this manually once you are satisfied.

Rebasing: Whenever PR is behind base branch, or you tick the rebase/retry checkbox.

🔕 Ignore: Close this PR and you won't be reminded about this update again.


  • If you want to rebase/retry this PR, check this box

This PR has been generated by Mend Renovate CLI.

@xdev-renovate
xdev-renovate force-pushed the renovate/org.mariadb.jdbc-mariadb-java-client-3.x branch from 60834f8 to 9a2b38a Compare August 4, 2026 05:47
@xdev-renovate
xdev-renovate force-pushed the renovate/org.mariadb.jdbc-mariadb-java-client-3.x branch from 9a2b38a to b142204 Compare August 5, 2026 05:45
@AB-xdev
AB-xdev merged commit 3c07534 into develop Aug 10, 2026
5 checks passed
@AB-xdev
AB-xdev deleted the renovate/org.mariadb.jdbc-mariadb-java-client-3.x branch August 10, 2026 15:06
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants