Skip to content

chore(deps): update dependency com.typesafe.play:sbt-plugin to v2.9.10#3916

Merged
vlsi merged 1 commit intopgjdbc:masterfrom
renovate-bot:renovate/com.typesafe.play-sbt-plugin-2.x
Jan 19, 2026
Merged

chore(deps): update dependency com.typesafe.play:sbt-plugin to v2.9.10#3916
vlsi merged 1 commit intopgjdbc:masterfrom
renovate-bot:renovate/com.typesafe.play-sbt-plugin-2.x

Conversation

@renovate-bot
Copy link
Contributor

This PR contains the following updates:

Package Type Update Change
com.typesafe.play:sbt-plugin plugin patch 2.9.92.9.10

Warning

Some dependencies could not be looked up. Check the Dependency Dashboard for more information.


Release Notes

playframework/playframework (com.typesafe.play:sbt-plugin)

v2.9.10: Play 2.9.10

Compare Source

We are pleased to announce the release of Play 2.9.10! 🎉

📗 About this Release

This release fixes several bugs and addresses reported security vulnerabilities (CVEs) and - as always - updates dependencies. We strongly recommend upgrading at your earliest convenience.

If you're considering upgrading to Play 2.9, please check the Play 2.9 release announcement for highlights and further details on how to migrate. Many projects have already smoothly upgraded to Play 2.9.

Noteworthy Pull Request
  • playframework/play-json#1226 Avoid running out of memory when parsing heavily nested arrays or objects by @​mkurz
    We now limit the maximum allowed nesting depth of JSON structures (arrays, objects, or a mix of both) to 1000.
    This limit can be adjusted using the system property play.json.parser.maxNestingDepth.
    We assume a depth of 1000 should be more than sufficient for virtually all real-world use cases.
    This change helps prevent both potential OutOfMemoryErrors and StackOverflowErrors.
    The latter, however, is not a concern for Play JSON, since it already uses a @​tailrec-optimized parsing method.
    As a result, Play JSON is not affected by GHSA-h46c-h94j-95f3, which specifically addresses StackOverflowError risks.
    This improvement is simply an additional safety measure.
  • #​13685 [2.9.x] Bump to lz4-java 1.10.1 to fix CVE-2025-66566 and CVE‐2025‐12183 by @​mkurz
  • #​13707 [2.9.x] Netty 4.1.130.Final (backport #​13706) to fix CVE-2025-67735 by @​mkurz
  • Upgrade ch.qos.logback:logback-core to fix CVE-2025-11226 (see "Patch updates" below)

Following pull requests got merged for this release:

For more details see the full list of changes and the 2.9.10 milestone.

❤️ Thanks to our premium sponsors!

If you find this OSS project useful for work, please consider asking your company to support it by becoming a sponsor.
You can also individually sponsor the project by becoming a backer.

🙇 Thanks to our contributors

Finally, thanks to the community for their help with detailed bug reports, discussions about new features and pull request reviews. This project is only possible due to the help we had from amazing contributors.
Special thanks to all code contributors who helped with this particular release (they are listed below)!


Configuration

📅 Schedule: Branch creation - "every 3 weeks on Monday" (UTC), Automerge - At any time (no schedule defined).

🚦 Automerge: Disabled by config. Please merge this manually once you are satisfied.

Rebasing: Whenever PR becomes conflicted, or you tick the rebase/retry checkbox.

🔕 Ignore: Close this PR and you won't be reminded about this update again.


  • If you want to rebase/retry this PR, check this box

This PR was generated by Mend Renovate. View the repository job log.

@forking-renovate forking-renovate bot added the dependencies Pull requests that update a dependency file label Jan 19, 2026
@vlsi vlsi merged commit 0bf6905 into pgjdbc:master Jan 19, 2026
16 of 17 checks passed
@renovate-bot renovate-bot deleted the renovate/com.typesafe.play-sbt-plugin-2.x branch January 19, 2026 17:23
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

dependencies Pull requests that update a dependency file

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants

Comments