Skip to content

build(deps): Bump com.babelqueue:babelqueue-core from 1.0.0 to 1.7.0 - #8

Open
dependabot[bot] wants to merge 1 commit into
mainfrom
dependabot/maven/com.babelqueue-babelqueue-core-1.7.0
Open

dependabot[bot] wants to merge 1 commit into
mainfrom
dependabot/maven/com.babelqueue-babelqueue-core-1.7.0

Conversation

@dependabot

@dependabot dependabot Bot commented on behalf of github Oct 3, 2026

Copy link
Copy Markdown
Contributor

Bumps com.babelqueue:babelqueue-core from 1.0.0 to 1.7.0.

Release notes

Sourced from com.babelqueue:babelqueue-core's releases.

v1.7.0

Full Changelog: BabelQueue/babelqueue-java@v1.6.0...v1.7.0

v1.6.0

Full Changelog: BabelQueue/babelqueue-java@v1.5.0...v1.6.0

v1.5.0

Full Changelog: BabelQueue/babelqueue-java@v1.4.0...v1.5.0

v1.4.0

Full Changelog: BabelQueue/babelqueue-java@v1.3.0...v1.4.0

v1.3.0

What's Changed

Full Changelog: BabelQueue/babelqueue-java@v1.2.0...v1.3.0

v1.2.0

What's Changed

Full Changelog: BabelQueue/babelqueue-java@v1.1.0...v1.2.0

v1.1.0

What's Changed

New Contributors

Full Changelog: BabelQueue/babelqueue-java@v1.0.0...v1.1.0

Changelog

Sourced from com.babelqueue:babelqueue-core's changelog.

[1.7.0] - 2026-06-21

Added

  • Runtime GDPR field encryption (ADR-0030) in the new optional com.babelqueue.gdpr module — the SDK-enforcement half of the registry's x-gdpr-sensitive declaration. babelqueue-registry only declares and audits which data fields are personal data; this module enforces it on the wire: a producer encrypts each marked leaf before publish, a consumer decrypts it after decode. It is the Java mirror of the Go reference, so every SDK round-trips byte-for-byte. Standalone and opt-in.
    • Cipher is a caller-provided interface (encrypt(byte[]) / decrypt(String)) — a seam onto KMS/Vault/HSM/tokenisation, so the core pulls no crypto dependency (GR-7). AesGcmCipher is a JDK-only reference (javax.crypto, AES-256-GCM, a fresh random 12-byte IV prepended, Base64); the caller owns the key. A wrong key or tampered ciphertext fails GCM authentication and throws rather than returning corrupt plaintext.
    • Gdpr.protect(data, schema, cipher) / Gdpr.unprotect(...) rewrite each x-gdpr-sensitive leaf in place: the value is canonically JSON-encoded then replaced by the ciphertext string, and unprotect decodes the decrypted bytes back — so the round-trip is byte-for-byte (a number restores to a number, an object to an object). An absent path is skipped; a non-string leaf in unprotect is left untouched (idempotent re-runs); a value the cipher cannot open throws DecryptException so the message takes retry / dead-letter.
    • SensitivePaths.of(schema) (+ the SensitivePath record) in com.babelqueue.schema walk a decoded JSON Schema for the x-gdpr-sensitive marks (boolean true or a non-empty string category), descending nested objects, array items (field[]) and the root. The keyword is validation-neutral — annotating a schema is never a breaking change.
    • The wire envelope stays frozen: only the value of a sensitive field changes (to a ciphertext string), so data is still pure JSON (GR-3), meta.schema_version stays 1 and trace_id is untouched (GR-4). This is additive and opt-in.

[1.6.0] - 2026-06-21

Added

  • Transactional-outbox helper (ADR-0029) in the new optional com.babelqueue.outbox module — the producer-side mirror of the consumer-side idempotency helper (ADR-0022). It removes the producer dual write: the message is persisted into the caller's own database, inside the caller's own transaction, so it commits or rolls back atomically with the business data, and a separate relay publishes the durable rows afterwards. Exactly-once handoff into the broker, then at-least-once on the wire as always (consumers still dedupe on meta.id).
    • Outbox.write(envelope) encodes via the frozen EnvelopeCodec and hands the bytes verbatim to the store — the outbox stores the wire envelope byte-for-byte and never adds an envelope field (GR-1, schema_version stays 1); trace_id is preserved end-to-end (GR-4) and the relay publishes those exact bytes (GR-5).
    • OutboxStore is the persistence contract the caller binds to their own DB (JDBC) — the core adds no DB driver (GR-7); InMemoryOutboxStore is the reference for tests/single-process demos. The transaction boundary is the caller's: Outbox never begins/commits.
    • OutboxRelay.flush()/drain(maxPasses) publish a batch through the publish-only OutboxTransport seam, marking a row published only after the transport accepts it; a throwing publish is caught, recorded via markFailed with a bounded linear backoff (injectable Sleeper so tests stay instant), and the row stays pending — one

... (truncated)

Commits
  • 920fcd0 feat(gdpr): runtime field encryption for x-gdpr-sensitive — Java core (ADR-0030)
  • 804be46 feat(outbox): transactional outbox helper — Java core (ADR-0029)
  • dc8da67 feat(otel): W3C traceparent transport-header propagation — Java core (ADR-0028)
  • a5a1f5b feat(replay): Replay-Bypass guard — skip external side-effects on a deliberat...
  • 0ddfbf9 chore(release): v1.3.0
  • a73865c feat(redrive): DLQ redrive tooling — safe replay (ADR-0026) (#3)
  • 8eddb59 chore(release): v1.2.0
  • 85f98a8 feat(otel): optional OpenTelemetry tracing module (ADR-0025) (#2)
  • a601393 build: bump central-publishing-maven-plugin 0.7.0 -> 0.11.0
  • ebe0836 chore(release): v1.1.0
  • Additional commits viewable in compare view

Dependabot compatibility score

Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting @dependabot rebase.


Dependabot commands and options

You can trigger Dependabot actions by commenting on this PR:

  • @dependabot rebase will rebase this PR
  • @dependabot recreate will recreate this PR, overwriting any edits that have been made to it
  • @dependabot show <dependency name> ignore conditions will show all of the ignore conditions of the specified dependency
  • @dependabot ignore this major version will close this PR and stop Dependabot creating any more for this major version (unless you reopen the PR or upgrade to it yourself)
  • @dependabot ignore this minor version will close this PR and stop Dependabot creating any more for this minor version (unless you reopen the PR or upgrade to it yourself)
  • @dependabot ignore this dependency will close this PR and stop Dependabot creating any more for this dependency (unless you reopen the PR or upgrade to it yourself)

Bumps [com.babelqueue:babelqueue-core](https://github.com/BabelQueue/babelqueue-java) from 1.0.0 to 1.7.0.
- [Release notes](https://github.com/BabelQueue/babelqueue-java/releases)
- [Changelog](https://github.com/BabelQueue/babelqueue-java/blob/main/CHANGELOG.md)
- [Commits](BabelQueue/babelqueue-java@v1.0.0...v1.7.0)

---
updated-dependencies:
- dependency-name: com.babelqueue:babelqueue-core
  dependency-version: 1.7.0
  dependency-type: direct:production
  update-type: version-update:semver-minor
...

Signed-off-by: dependabot[bot] <support@github.com>
@dependabot dependabot Bot added dependencies Pull requests that update a dependency file java Pull requests that update java code labels Oct 3, 2026
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

dependencies Pull requests that update a dependency file java Pull requests that update java code

Projects

None yet

Development

Successfully merging this pull request may close these issues.

0 participants