Skip to content

Bump org.glassfish.main.extras:glassfish-embedded-all from 7.1.0 to 8.0.4 - #1524

Open
dependabot[bot] wants to merge 1 commit into
masterfrom
dependabot/maven/org.glassfish.main.extras-glassfish-embedded-all-8.0.4
Open

Bump org.glassfish.main.extras:glassfish-embedded-all from 7.1.0 to 8.0.4#1524
dependabot[bot] wants to merge 1 commit into
masterfrom
dependabot/maven/org.glassfish.main.extras-glassfish-embedded-all-8.0.4

Conversation

@dependabot

@dependabot dependabot Bot commented on behalf of github Aug 9, 2026

Copy link
Copy Markdown
Contributor

Bumps org.glassfish.main.extras:glassfish-embedded-all from 7.1.0 to 8.0.4.

Release notes

Sourced from org.glassfish.main.extras:glassfish-embedded-all's releases.

8.0.4

Eclipse GlassFish is an application server, implementing Jakarta EE and MicroProfile. This release corresponds with the Jakarta EE 11 specification. Eclipse GlassFish 8 is production ready, commercially supported by OmniFish, and requires JDK 21 or higher.

Release Overview

Version 8.0.4 focuses on the upgrade path from GlassFish 7, on Embedded GlassFish, and on CDI integration.

Domains created by GlassFish 7.0.x now have their legacy JKS/JCEKS security stores migrated to PKCS12, upgrading a domain that contains a cluster works again, and the migrated domain-passwords.p12 is synchronized to the instances.

Embedded GlassFish propagates deployment failures, deletes its temporary directories through a JVM shutdown hook and restricts them to the current user, and ships real javadoc and sources Maven artifacts.

Jakarta REST artifacts can be injected with @Inject out of the box now that jersey-cdi-rs-inject is bundled, @Transactional rollbackOn/dontRollbackOn carried by CDI stereotypes are resolved, and the thread-context-classloader hack in the Weld bean deployment archive has been replaced by the per-BDA ResourceLoader SPI.

Upgrading from GlassFish 7.0.x

Upgrading a domain from GlassFish 7.0.x migrates its legacy JKS/JCEKS security stores to PKCS12, so no manual conversion of the domain keystore and truststore is needed. Domains that contain a cluster upgrade correctly again, and the resulting domain-passwords.p12 is synchronized to the instances.

Security Fixes

A complete GlassFish security summary is provided by OmniFish here: https://omnifish.ee/glassfish-security-summary/

Fixes

Improvements

... (truncated)

Changelog

Sourced from org.glassfish.main.extras:glassfish-embedded-all's changelog.

Releasing a new GlassFish version

In this example we assume 8.0.4. If any step failed, you have to resolve the issue and start from the appropriate step again.

  1. Create a release branch RELEASE_8.0.4 and push it to the Eclipse GlassFish GitHub repository.
  2. Open glassfish-release
  3. Click Build with parameters in menu.
    • releaseVersion = 8.0.4
    • nextVersion = 8.0.5-SNAPSHOT
    • click [Build] button.
  4. Wait for it to finish successfully
  5. Verify that everything was done:
    1. Verify that the deployment is present in Maven Central Deployments
      • It is possible that you will not have permissions to visit the namespace. Ask project leads or check if expected artifacts made it to Maven Central, then this was obviously successful.
    2. Verify that a new 8.0.4 tag was created.
    3. Verify that the release branch changed the number to the nextVersion value.
  6. Create a Draft PR based on this branch.
  7. Find the Glassfish Full Profile Distribution on the page of the release build under glassfish-release and copy the URL of the zip file.
  8. Run the TCKs against the result artifact - alternatively you can deploy to Maven Central Snapshots using glassfish-deploy-snapshots and refer zip from the build or from Maven Central Snapshots (same file). As another alternative you can run the TCK on any other infrastructure.
  9. Create the release on GitHub: click "Draft a new release"
  10. Create the release on Eclipse: "Create a new release"
  11. If it is a version with important feature changes, ask for a release review. Remember that it will take more than week.
  12. Create the release on Glassfish.org. Do a PR for the main branch with:
    • an update for the website in docs/website/src/main/resources:
      • in download_gf8.md, create a section for the new version at the top, based on the previous version. Update the info based on the release notes on GitHub
      • in download.md, replace information in the "Eclipse GlassFish 8.x" section at the top with info for the new version in download_gf8.md
      • check README.md and update the Latest News chapter.
    • with an update for the docs:
      • Update the property glassfish.version.8x with the released version in docs/pom.xml
  13. Open Maven Central Deployments and click the Publish button. Maven Central then distributes artifacts so they will become reachable to anyone referring Maven Central Repository.
  14. Verify that it's present in Maven Central (usually takes few minutes now)
  15. Upload the new release to the Eclipse download folder. Go to glassfish-copy-to-downloads
    • Enter the version to copy; 8.0.4
    • click [Build] button
  16. If everything is OK, then merge the PR.
  17. Delete the branch after merge, only tag will remain.
  18. Create a new Eclipse GlassFish Docker Image - follow Eclipse GlassFish Docker Image Wiki
Commits

Dependabot compatibility score

Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting @dependabot rebase.


Dependabot commands and options

You can trigger Dependabot actions by commenting on this PR:

  • @dependabot rebase will rebase this PR
  • @dependabot recreate will recreate this PR, overwriting any edits that have been made to it
  • @dependabot show <dependency name> ignore conditions will show all of the ignore conditions of the specified dependency
  • @dependabot ignore this major version will close this PR and stop Dependabot creating any more for this major version (unless you reopen the PR or upgrade to it yourself)
  • @dependabot ignore this minor version will close this PR and stop Dependabot creating any more for this minor version (unless you reopen the PR or upgrade to it yourself)
  • @dependabot ignore this dependency will close this PR and stop Dependabot creating any more for this dependency (unless you reopen the PR or upgrade to it yourself)

Bumps [org.glassfish.main.extras:glassfish-embedded-all](https://github.com/eclipse-ee4j/glassfish) from 7.1.0 to 8.0.4.
- [Release notes](https://github.com/eclipse-ee4j/glassfish/releases)
- [Changelog](https://github.com/eclipse-ee4j/glassfish/blob/8.0.4/RELEASE.md)
- [Commits](eclipse-ee4j/glassfish@7.1.0...8.0.4)

---
updated-dependencies:
- dependency-name: org.glassfish.main.extras:glassfish-embedded-all
  dependency-version: 8.0.4
  dependency-type: direct:production
  update-type: version-update:semver-major
...

Signed-off-by: dependabot[bot] <support@github.com>
@dependabot dependabot Bot added dependencies Pull requests that update a dependency file java Pull requests that update Java code labels Aug 9, 2026
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

dependencies Pull requests that update a dependency file java Pull requests that update Java code

Projects

None yet

Development

Successfully merging this pull request may close these issues.

0 participants