Skip to content

Bump org.apache.tika:tika-core from 3.3.2 to 4.0.0 - #167

Merged
SibeiC merged 1 commit into
masterfrom
dependabot/maven/org.apache.tika-tika-core-4.0.0
Aug 27, 2026
Merged

SibeiC merged 1 commit into
masterfrom
dependabot/maven/org.apache.tika-tika-core-4.0.0

Conversation

@dependabot

@dependabot dependabot Bot commented on behalf of github Aug 27, 2026

Copy link
Copy Markdown
Contributor

Bumps org.apache.tika:tika-core from 3.3.2 to 4.0.0.

Changelog

Sourced from org.apache.tika:tika-core's changelog.

Release 4.1.0 - unreleased

  • Add Micrometer reporting and opt-in endpoint for tika-server (TIKA-4839).

  • Improve spooling/decrease number of spills to disk (TIKA-4835).

  • Fixed a bug that made per-request (parse-context) configuration unusable for parsers that lock some config fields against caller modification -- Tess4J, the VLM parsers and the OpenAI image-embedding parser. Any such config threw, including an empty one: the defaults were deep-copied through their own setters, which the runtime config overrides to reject caller input, so the copy tripped the parser's own guards before the caller's JSON was read. Locked fields are still rejected when a caller actually sets them. Configuration supplied at initialization time (the "parsers" section) was never affected (TIKA-4843).

  • OOXML parsers flag package parts that are unreachable through the OPC relationship graph: msoffice:has-unreferenced-parts (boolean) and msoffice:unreferenced-part-names. Purely structural (no bytes are inspected; content types come from [Content_Types].xml by extension), so expect false positives from tools that leave orphan parts behind. A hiding place a raw-ZIP scanner can still see, not a statement about what Tika parsed. Applies to Word, Excel, PowerPoint and Visio OOXML (including macro-enabled variants); XPS links content by markup rather than relationships and is not checked (TIKA-4837).

  • Shared pipes server (useSharedServer: true, not the default): a client whose in-flight parse was killed by another client's restart could restart the healthy replacement. ensureRunning holds its lock across the whole fork, so siblings cannot report a dead worker until after the replacement is up, and the pending-restart flag carried no process identity -- so a report about the process that just died was applied to its successor, which was then destroyed and re-forked. One worker death produced two restarts and a second round of destroyed in-flight work; under sustained concurrent load it sustained itself at one spurious restart per round, appearing as periodic unexplained worker churn and intermittent parse failures that succeed on retry. Each fork now carries a generation that clients capture when they connect and hand back with every report, and reports about a superseded process are dropped. Also fixed in shared mode: ensureRunning could fork a replacement after shutdown() that nothing owned and nothing would ever destroy, and an interrupt during process teardown left the process handle pointing at a killed process and leaked the temp directory. Affects 4.0.0 and earlier (TIKA-4844).

  • tika-pipes: the cache memory budget (how much rewindable content a forked worker keeps in memory before spilling to disk; new since 4.0.0, which had no budget at all) defaults to a quarter of the fork's heap, so raising -Xmx raises it. It is one pool per forked JVM shared by all of its threads. -Dtika.pipes.cacheMemoryBudgetBytes in forkedJvmArgs overrides it (below the quarter-heap ceiling; <=0 disables); the fork logs the value and its

... (truncated)

Commits
  • 514e1b3 [maven-release-plugin] prepare release 4.0.0-rc1
  • 4e39e07 revert second rc1 attempt
  • 7975986 javadocs take 42
  • 95d4235 [maven-release-plugin] prepare for next development iteration
  • 666289b [maven-release-plugin] prepare release 4.0.0-rc1
  • c9f6585 TIKA-4808 - revert aborted 4.0.0-rc1 release commits; fix per-module javadoc ...
  • 41183e7 [maven-release-plugin] prepare for next development iteration
  • 5dd7fc7 [maven-release-plugin] prepare release 4.0.0-rc1
  • 4b231cf TIKA-4808 -- prep CHANGES.txt for release
  • 532a685 TIKA-4808 - remove access to the network parser from cli (#3036)
  • Additional commits viewable in compare view

Dependabot compatibility score

Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting @dependabot rebase.


Dependabot commands and options

You can trigger Dependabot actions by commenting on this PR:

  • @dependabot rebase will rebase this PR
  • @dependabot recreate will recreate this PR, overwriting any edits that have been made to it
  • @dependabot show <dependency name> ignore conditions will show all of the ignore conditions of the specified dependency
  • @dependabot ignore this major version will close this PR and stop Dependabot creating any more for this major version (unless you reopen the PR or upgrade to it yourself)
  • @dependabot ignore this minor version will close this PR and stop Dependabot creating any more for this minor version (unless you reopen the PR or upgrade to it yourself)
  • @dependabot ignore this dependency will close this PR and stop Dependabot creating any more for this dependency (unless you reopen the PR or upgrade to it yourself)

Bumps [org.apache.tika:tika-core](https://github.com/apache/tika) from 3.3.2 to 4.0.0.
- [Changelog](https://github.com/apache/tika/blob/main/CHANGES.txt)
- [Commits](apache/tika@3.3.2...4.0.0)

---
updated-dependencies:
- dependency-name: org.apache.tika:tika-core
  dependency-version: 4.0.0
  dependency-type: direct:production
  update-type: version-update:semver-major
...

Signed-off-by: dependabot[bot] <support@github.com>
@dependabot dependabot Bot added dependencies Pull requests that update a dependency file java Pull requests that update java code labels Aug 27, 2026
@SibeiC
SibeiC merged commit 1700c6a into master Aug 27, 2026
6 checks passed
@dependabot
dependabot Bot deleted the dependabot/maven/org.apache.tika-tika-core-4.0.0 branch August 27, 2026 11:17
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

dependencies Pull requests that update a dependency file java Pull requests that update java code

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant