Skip to content

Bump com.googlecode.plist:dd-plist from 1.3 to 1.18 in /server#1

Open
dependabot[bot] wants to merge 1 commit into
devfrom
dependabot/maven/server/com.googlecode.plist-dd-plist-1.18
Open

Bump com.googlecode.plist:dd-plist from 1.3 to 1.18 in /server#1
dependabot[bot] wants to merge 1 commit into
devfrom
dependabot/maven/server/com.googlecode.plist-dd-plist-1.18

Conversation

@dependabot

@dependabot dependabot Bot commented on behalf of github Jun 17, 2026

Copy link
Copy Markdown

Bumps com.googlecode.plist:dd-plist from 1.3 to 1.18.

Release notes

Sourced from com.googlecode.plist:dd-plist's releases.

Release 1.18

Changes from 1.17 to 1.18:

  • Switched target language level from 1.5 to 1.6
  • NSObject.wrap() has been replaced by an improved serialization logic implemented in NSObject.fromJavaObject() (#21)
  • Fixed serialization of byte arrays as NSData
  • Fixed parsing of UTF-8 encoded ASCII property lists (#25)
  • Protect XML parser against external XXE attacks (#26)
  • Fixed handling of empty files (#30)
  • Added support for hexadecimal integer notation in XML property lists (#30)
  • Improved binary encoding of NSDictionary to generate IDs for the keys like Apple's reference implementation does
  • Many code cleanups

Release 1.17

Changes from 1.17 to 1.16:

  • Fixed issue with reading too many bytes from certain input streams, e.g. ZipInputStream (See Issue #3)
  • Reduced memory allocations of binary property list parser (Thanks to @​lumley)

Release 1.16

Changes from R1.16 to R1.13

  • Fix parsing of XML and ASCII property lists that have a Unicode Byte Order Mark
  • Improve serialization of null values

Changes from R1.13 to R1.8

  • Fix exception when parsing binary property lists whose size is exactly a multiple of 512
  • Improve identification of property list type while parsing
  • Do not parse unquoted strings that only contain digits as NSNumber instances in ASCII property lists as this is against the format specification

Changes from R1.8 to R1.3

  • The parsing methods now throw more specific exceptions depending on the exact error
  • Fix serialization of arrays
Commits
  • c9eea3f Release 1.18
  • 4313bae Update POM
  • 58fc9bd Test example code to parse a .strings file using the ASCII property list parser
  • f96e82d Added support for empty plist files (#30)
  • 2976141 The file /System/Library/Frameworks/Carbon.framework/Versions/Current/Framewo...
  • 2c8c164 Merge pull request #25 from christopheplat/master
  • 2120e77 Merge pull request #26 from joval/master
  • 8d9e08f Modifications per Daniel Dreibrodt.
  • 8c954e8 1) Take steps to guard against external XXE attacks (except, note that <!DOCT...
  • 101e5a6 Properly parse unescaped UTF8 characters in quoted strings
  • Additional commits viewable in compare view

Dependabot compatibility score

Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting @dependabot rebase.


Dependabot commands and options

You can trigger Dependabot actions by commenting on this PR:

  • @dependabot rebase will rebase this PR
  • @dependabot recreate will recreate this PR, overwriting any edits that have been made to it
  • @dependabot show <dependency name> ignore conditions will show all of the ignore conditions of the specified dependency
  • @dependabot ignore this major version will close this PR and stop Dependabot creating any more for this major version (unless you reopen the PR or upgrade to it yourself)
  • @dependabot ignore this minor version will close this PR and stop Dependabot creating any more for this minor version (unless you reopen the PR or upgrade to it yourself)
  • @dependabot ignore this dependency will close this PR and stop Dependabot creating any more for this dependency (unless you reopen the PR or upgrade to it yourself)
    You can disable automated security fix PRs for this repo from the Security Alerts page.

Bumps [com.googlecode.plist:dd-plist](https://github.com/3breadt/dd-plist) from 1.3 to 1.18.
- [Release notes](https://github.com/3breadt/dd-plist/releases)
- [Commits](3breadt/dd-plist@dd-plist-1.3...dd-plist-1.18)

---
updated-dependencies:
- dependency-name: com.googlecode.plist:dd-plist
  dependency-version: '1.18'
  dependency-type: direct:production
...

Signed-off-by: dependabot[bot] <support@github.com>
@dependabot dependabot Bot added dependencies Pull requests that update a dependency file java Pull requests that update java code labels Jun 17, 2026
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

dependencies Pull requests that update a dependency file java Pull requests that update java code

Projects

None yet

Development

Successfully merging this pull request may close these issues.

0 participants