Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Update dependency org.springframework.security:spring-security-crypto to v6 #776

Open
wants to merge 1 commit into
base: master
Choose a base branch
from

Conversation

renovate[bot]
Copy link
Contributor

@renovate renovate bot commented Nov 7, 2023

This PR contains the following updates:

Package Change Age Adoption Passing Confidence
org.springframework.security:spring-security-crypto (source) 5.8.8 -> 6.3.4 age adoption passing confidence

Warning

Some dependencies could not be looked up. Check the Dependency Dashboard for more information.


Release Notes

spring-projects/spring-security (org.springframework.security:spring-security-crypto)

v6.3.4

Compare Source

🪲 Bug Fixes

  • Annotation expression template processing should not fail on Class parameter types #​15711
  • Disabling credentials erasure on custom AuthenticationManager is not working #​15808
  • Documentation inconsistency in AuthorizationManager's verify method return type #​15822
  • Methods annotated with @PostFilter are processed twice by PostFilterAuthorizationMethodInterceptor #​15676
  • OidcBackChannelLogoutTokenValidator should not construct when missing OIDC Provider Issuer #​15868
  • SecurityJackson2Modules.getModules(): Cannot load module org.springframework.security.cas.jackson2.CasJackson2Module #​15767
  • The additionalParameters array parameter of OAuth2AuthorizationRequest causes the authorizationRequestUri to be incorrect #​15829

🔨 Dependency Upgrades

  • Bump ch.qos.logback:logback-classic from 1.5.10 to 1.5.11 #​15926
  • Bump io.micrometer:micrometer-observation from 1.12.10 to 1.12.11 #​15917
  • Bump io.mockk:mockk from 1.13.12 to 1.13.13 #​15897
  • Bump io.projectreactor:reactor-bom from 2023.0.10 to 2023.0.11 #​15925
  • Bump jakarta.servlet.jsp.jstl:jakarta.servlet.jsp.jstl-api from 3.0.1 to 3.0.2 #​15694
  • Bump org-eclipse-jetty from 11.0.23 to 11.0.24 #​15731
  • Bump org.jfrog.buildinfo:build-info-extractor-gradle from 4.33.21 to 4.33.22 #​15761
  • Bump org.junit:junit-bom from 5.10.4 to 5.10.5 #​15883
  • Bump org.springframework.data:spring-data-bom from 2024.0.4 to 2024.0.5 #​15958
  • Bump org.springframework.ldap:spring-ldap-core from 3.2.6 to 3.2.7 #​15944
  • Bump org.springframework:spring-framework-bom from 6.1.13 to 6.1.14 #​15945

🔩 Build Updates

  • Bump @antora/collector-extension from 1.0.0-beta.2 to 1.0.0-beta.3 in /docs #​15907
  • Bump @springio/asciidoctor-extensions from 1.0.0-alpha.13 to 1.0.0-alpha.14 in /docs #​15836
  • Migrate slack notifications to GChat #​15668
  • Release 6.3.4 #​15964
  • Update eclipse/vscode configuration to use -parameters #​15681

❤️ Contributors

Thank you to all the contributors who worked on this release:

@​dependabot[bot] and @​kse-music

v6.3.3

Compare Source

🪲 Bug Fixes

  • ObservationRegistry is never post-processed #​15658

🔨 Dependency Upgrades

  • Bump org-eclipse-jetty from 11.0.22 to 11.0.23 #​15664

❤️ Contributors

Thank you to all the contributors who worked on this release:

@​dependabot[bot]

v6.3.2

Compare Source

⭐ New Features

  • ActiveDirectoryLdapAuthenticationProvider does not implement support for multiple urls #​15495
  • Document the role of CredentialsContainer #​15321
  • OIDC Backchannel Logout should allow logout tokens having typ header of logout+jwt #​15410

🪲 Bug Fixes

  • A broken link in Spring Security reference #​15297
  • Documentation for ServletBearerExchangeFilterFunction incomplete or incorrect #​15460
  • EnableMethodSecurity should publish only one bean of each AuthorizationAdvisor #​15592
  • Fix Compromised Password Checker Docs Sample Not Working #​15305
  • Fix for #​15172 introduces significant performance degredation #​15324
  • Pre/PostAuthorize should not ignore HandleAuthorizationDenied#handlerClass when ApplicationContext is not provided #​15535
  • Update prerequisites documentation with Java 17 #​15340
  • Use Correct Meta-Annotation in Kotlin Sample #​15472
  • Using sec:authorize in JSPX causes 'java.lang.NullPointerException: Cannot invoke "jakarta.servlet.ServletRegistration.getClassName()" because "registration" is null' #​15440

🔨 Dependency Upgrades

  • Bump ch.qos.logback:logback-classic from 1.5.6 to 1.5.7 #​15619
  • Bump com.fasterxml.jackson:jackson-bom from 2.17.1 to 2.17.2 #​15374
  • Bump com.github.spullara.mustache.java:compiler from 0.9.13 to 0.9.14 #​15373
  • Bump io.micrometer:micrometer-observation from 1.12.7 to 1.12.8 #​15383
  • Bump io.micrometer:micrometer-observation from 1.12.8 to 1.12.9 #​15581
  • Bump io.mockk:mockk from 1.13.11 to 1.13.12 #​15430
  • Bump io.projectreactor:reactor-bom from 2023.0.7 to 2023.0.8 #​15388
  • Bump io.projectreactor:reactor-bom from 2023.0.8 to 2023.0.9 #​15597
  • Bump jakarta.servlet.jsp.jstl:jakarta.servlet.jsp.jstl-api from 3.0.0 to 3.0.1 #​15582
  • Bump org-apache-maven-resolver from 1.9.20 to 1.9.21 #​15372
  • Bump org-apache-maven-resolver from 1.9.21 to 1.9.22 #​15545
  • Bump org-eclipse-jetty from 11.0.21 to 11.0.22 #​15356
  • Bump org.apache.maven:maven-resolver-provider from 3.9.7 to 3.9.8 #​15268
  • Bump org.apache.maven:maven-resolver-provider from 3.9.8 to 3.9.9 #​15642
  • Bump org.gretty:gretty from 4.1.4 to 4.1.5 #​15431
  • Bump org.hibernate.orm:hibernate-core from 6.4.9.Final to 6.4.10.Final #​15530
  • Bump org.jetbrains.kotlin:kotlin-bom from 1.9.24 to 1.9.25 #​15456
  • Bump org.jetbrains.kotlin:kotlin-gradle-plugin from 1.9.24 to 1.9.25 #​15455
  • Bump org.jfrog.buildinfo:build-info-extractor-gradle from 4.33.19 to 4.33.20 #​15267
  • Bump org.junit:junit-bom from 5.10.2 to 5.10.3 #​15315
  • Bump org.skyscreamer:jsonassert from 1.5.1 to 1.5.3 #​15336
  • Bump org.slf4j:slf4j-api from 2.0.13 to 2.0.14 #​15529
  • Bump org.slf4j:slf4j-api from 2.0.14 to 2.0.15 #​15546
  • Bump org.slf4j:slf4j-api from 2.0.15 to 2.0.16 #​15571
  • Bump org.springframework.data:spring-data-bom from 2024.0.1 to 2024.0.2 #​15421
  • Bump org.springframework.data:spring-data-bom from 2024.0.2 to 2024.0.3 #​15643
  • Bump org.springframework.ldap:spring-ldap-core from 3.2.4 to 3.2.6 #​15620
  • Bump org.springframework:spring-framework-bom from 6.1.10 to 6.1.11 #​15402
  • Bump org.springframework:spring-framework-bom from 6.1.11 to 6.1.12 #​15613
  • Bump org.springframework:spring-framework-bom from 6.1.9 to 6.1.10 #​15279

🔩 Build Updates

  • Automate check of expected branch version #​15310
  • Bump @antora/collector-extension from 1.0.0-alpha.4 to 1.0.0-alpha.6 in /docs #​15449
  • Bump @antora/collector-extension from 1.0.0-alpha.6 to 1.0.0-alpha.7 in /docs #​15482
  • Bump @antora/collector-extension from 1.0.0-alpha.7 to 1.0.0-beta.1 in /docs #​15560
  • Bump @antora/collector-extension from 1.0.0-beta.1 to 1.0.0-beta.2 in /docs #​15637
  • Bump @springio/antora-extensions from 1.11.1 to 1.12.0 in /docs #​15418
  • Bump @springio/antora-extensions from 1.12.0 to 1.13.0 in /docs #​15517
  • Bump @springio/antora-extensions from 1.13.0 to 1.13.1 in /docs #​15561
  • Bump @springio/antora-extensions from 1.13.1 to 1.14.2 in /docs #​15636
  • Bump @springio/asciidoctor-extensions from 1.0.0-alpha.10 to 1.0.0-alpha.11 in /docs #​15419
  • Bump @springio/asciidoctor-extensions from 1.0.0-alpha.11 to 1.0.0-alpha.12 in /docs #​15515
  • Bump antora from 3.2.0-alpha.4 to 3.2.0-alpha.5 in /docs #​15329
  • Bump antora from 3.2.0-alpha.5 to 3.2.0-alpha.6 in /docs #​15480
  • Bump com.gradle.develocity from 3.17.5 to 3.17.6 #​15464
  • Bump io-spring-javaformat from 0.0.42 to 0.0.43 #​15650
  • Fix typos and formatting in documentation #​15380
  • Migrate slack notifications to GChat #​15505
  • Use explicit types instead of var #​15537

❤️ Contributors

Thank you to all the contributors who worked on this release:

@​Kehrlann, @​dependabot[bot], and @​tahakorkem

v6.3.1

Compare Source

⭐ New Features

  • Clarify the behavior of Concurrent Session Management when an IdP is involved #​15071
  • Mention all required dependencies in LDAP documentation #​15245
  • Minor docs fix #​15144

🪲 Bug Fixes

  • AbstractRequestMatcherRegistry#requestMatchers should pick MvcRequestMatcher when using MockMvc #​15211
  • Assert WebSession is not null #​15179
  • DispatcherServletDelegatingRequestMatcher causes errors when running tests with MockMvc #​15197
  • Documentation clarification after #​12783 has been closed is needed. #​15208
  • Fix Java example in multitenanci.adoc #​15151
  • Fix Kotlin example in authorize-http-requests.adoc #​15129
  • Incorrect documentation for OIDC Back-Channel Logout #​15212
  • IpAddressMatcher.matches(String address) still accepts URLs #​15172
  • LDIF file on official documentation breaks the startup process #​15167
  • Link to article with remember-me-persistent-token strategy is broken #​15149
  • OpenSaml4AssertionValidator is not respecting clock skew settings #​15183
  • Resolving invalid CSRF token values is not consistent #​15186
  • spring-security/docs/modules/ROOT/pages/servlet/authorization /method-security #​15143
  • SpringOpaqueTokenIntrospector does not add scopes as granted authorities properly #​15165

🔨 Dependency Upgrades

  • Bump io.micrometer:micrometer-observation from 1.12.6 to 1.12.7 #​15225
  • Bump io.projectreactor:reactor-bom from 2023.0.6 to 2023.0.7 #​15229
  • Bump org.apache.directory.shared:shared-ldap from 0.9.15 to 0.9.19 #​15161
  • Bump org.apache.maven:maven-resolver-provider from 3.9.6 to 3.9.7 #​15168
  • Bump org.gretty:gretty from 4.1.3 to 4.1.4 #​15133
  • Bump org.hibernate.orm:hibernate-core from 6.4.8.Final to 6.4.9.Final #​15228
  • Bump org.hsqldb:hsqldb from 2.7.2 to 2.7.3 #​15193
  • Bump org.springframework.data:spring-data-bom from 2024.0.0 to 2024.0.1 #​15260
  • Bump org.springframework.ldap:spring-ldap-core from 3.2.3 to 3.2.4 #​15251
  • Bump org.springframework:spring-framework-bom from 6.1.7 to 6.1.8 #​15134
  • Bump org.springframework:spring-framework-bom from 6.1.8 to 6.1.9 #​15252

🔩 Build Updates

  • Bump @antora/collector-extension from 1.0.0-alpha.3 to 1.0.0-alpha.4 in /docs #​15159
  • Bump @springio/antora-extensions from 1.10.0 to 1.11.1 in /docs #​15141
  • Bump com.gradle.develocity from 3.17.4 to 3.17.5 #​15239
  • Bump gradle/gradle-build-action from 2 to 3 #​15157
  • Bump io-spring-javaformat from 0.0.41 to 0.0.42 #​15219
  • Bump org.jfrog.buildinfo:build-info-extractor-gradle from 4.33.15 to 4.33.16 #​15176
  • Bump org.jfrog.buildinfo:build-info-extractor-gradle from 4.33.16 to 4.33.17 #​15218
  • Bump org.jfrog.buildinfo:build-info-extractor-gradle from 4.33.17 to 4.33.19 #​15261
  • Bump spring-io/spring-doc-actions from 17ed79e to 5a57bcc #​15139

❤️ Contributors

Thank you to all the contributors who worked on this release:

@​dependabot[bot] and @​theHacker

v6.3.0

Compare Source

⭐ New Features

  • Add getters to OAuth2AuthorizedClientId #​13648
  • Add timeout defaults to JwtDecoders #​14890
  • doc: added hint to declare GrantedAuthorityDefaults as infrastructure bean #​15065
  • Improve logging for Global Authentication #​14711
  • Minor docs fix #​15043
  • Minor Documentation update on import needed for using Kotlin DSL #​14969
  • OAuth2 Client Authentication docs are incomplete #​14982
  • Proofread CasAuthenticationFilter documentation #​14883
  • Replace "Spring Boot 2.x" with "Spring Boot" #​14919
  • Simplify Disabling application/x-www-form-urlencoded Encoding Client ID and Secret #​14859
  • Support Specifying Identifier for relying-party-registrations Element #​14487
  • Update What's New in 6.3 #​14918

🪲 Bug Fixes

  • Do Not Invalidate Current Session When Its Registered #​15066
  • Fix MethodAuthorizationDeniedPostProcessor does not exist in java doc #​14955
  • fix docs error in AuthenticatedReactiveAuthorizationManager #​14979
  • OIDC Logout section is not shown in the navbar #​15113
  • Wrong information for RequestCacheAwareFilter in the Spring Security documentation. #​14996

🔨 Dependency Upgrades

  • Bump ch.qos.logback:logback-classic from 1.5.5 to 1.5.6 #​14926
  • Bump com.fasterxml.jackson:jackson-bom from 2.17.0 to 2.17.1 #​15010
  • Bump com.gradle.develocity from 3.17.2 to 3.17.3 #​15051
  • Bump com.gradle.develocity from 3.17.3 to 3.17.4 #​15104
  • Bump io.micrometer:micrometer-observation from 1.12.5 to 1.12.6 #​15068
  • Bump io.mockk:mockk from 1.13.10 to 1.13.11 #​15086
  • Bump io.projectreactor:reactor-bom from 2023.0.5 to 2023.0.6 #​15076
  • Bump org-apache-maven-resolver from 1.9.18 to 1.9.19 #​14940
  • Bump org-apache-maven-resolver from 1.9.19 to 1.9.20 #​14987
  • Bump org-aspectj from 1.9.22 to 1.9.22.1 #​15052
  • Bump org-bouncycastle from 1.78 to 1.78.1 #​14929
  • Bump org-eclipse-jetty from 11.0.20 to 11.0.21 #​15087
  • Bump org.hibernate.orm:hibernate-core from 6.4.4.Final to 6.4.5.Final #​14948
  • Bump org.hibernate.orm:hibernate-core from 6.4.5.Final to 6.4.6.Final #​14952
  • Bump org.hibernate.orm:hibernate-core from 6.4.6.Final to 6.4.7.Final #​14962
  • Bump org.hibernate.orm:hibernate-core from 6.4.7.Final to 6.4.8.Final #​14980
  • Bump org.jetbrains.kotlin:kotlin-bom from 1.9.23 to 1.9.24 #​15025
  • Bump org.jetbrains.kotlin:kotlin-gradle-plugin from 1.9.23 to 1.9.24 #​15026
  • Bump org.jetbrains.kotlinx:kotlinx-coroutines-bom from 1.8.0 to 1.8.1 #​15053
  • Bump org.jfrog.buildinfo:build-info-extractor-gradle from 4.33.13 to 4.33.15 #​14945
  • Bump org.springframework.data:spring-data-bom from 2024.0.0-RC1 to 2024.0.0 #​15103
  • Bump org.springframework:spring-framework-bom from 6.1.6 to 6.1.7 #​15088

🔩 Build Updates

  • Attach Antora Docs to Pull Requests #​15061
  • Bump com.github.spullara.mustache.java:compiler from 0.9.11 to 0.9.12 #​14986
  • Bump com.github.spullara.mustache.java:compiler from 0.9.12 to 0.9.13 #​14999
  • Bump io.spring.ge.conventions from 0.0.16 to 0.0.17 #​14963
  • Bump io.spring.gradle:spring-security-release-plugin from 1.0.2 to 1.0.3 #​14928
  • Consider Adding a Build Updates section to the release changelog #​15039

❤️ Contributors

Thank you to all the contributors who worked on this release:

@​Crain-32, @​Kehrlann, @​MrJovanovic13, @​ch4mpy, @​dependabot[bot], @​joaquinjsb, @​kse-music, @​madorb, @​rishiraj88, and @​vvaadd

v6.2.7

Compare Source

🪲 Bug Fixes

  • Disabling credentials erasure on custom AuthenticationManager is not working #​15807
  • Documentation inconsistency in AuthorizationManager's verify method return type #​15704
  • Fix code format in OIDC Logout docs #​15566
  • Fix OIDC Logout docs: Session Strategy vs. Registry #​15686
  • Methods annotated with @PostFilter are processed twice by PostFilterAuthorizationMethodInterceptor #​15675
  • Methods annotated with @PostFilter are processed twice by PostFilterAuthorizationMethodInterceptor #​15651
  • SecurityJackson2Modules.getModules(): Cannot load module org.springframework.security.cas.jackson2.CasJackson2Module #​15766
  • The additionalParameters array parameter of OAuth2AuthorizationRequest causes the authorizationRequestUri to be incorrect #​15828

🔨 Dependency Upgrades

  • Bump Gradle Wrapper from 8.10.1 to 8.10.2 #​15841
  • Bump io.micrometer:micrometer-observation from 1.12.10 to 1.12.11 #​15919
  • Bump io.mockk:mockk from 1.13.12 to 1.13.13 #​15896
  • Bump io.projectreactor:reactor-bom from 2023.0.10 to 2023.0.11 #​15927
  • Bump jakarta.servlet.jsp.jstl:jakarta.servlet.jsp.jstl-api from 3.0.1 to 3.0.2 #​15693
  • Bump org-eclipse-jetty from 11.0.23 to 11.0.24 #​15733
  • Bump org.junit:junit-bom from 5.10.4 to 5.10.5 #​15880
  • Bump org.springframework.data:spring-data-bom from 2023.1.10 to 2023.1.11 #​15962
  • Bump org.springframework.ldap:spring-ldap-core from 3.2.6 to 3.2.7 #​15946
  • Bump org.springframework:spring-framework-bom from 6.1.13 to 6.1.14 #​15947

🔩 Build Updates

  • Bump @antora/collector-extension from 1.0.0-beta.2 to 1.0.0-beta.3 in /docs #​15910
  • Bump @springio/asciidoctor-extensions from 1.0.0-alpha.13 to 1.0.0-alpha.14 in /docs #​15838
  • Bump Gradle Wrapper from 8.7 to 8.10 #​15609
  • CORS documentation should use UrlBasedCorsConfigurationSource #​15769
  • Migrate slack notifications to GChat #​15667
  • Release 6.2.7 #​15965
  • Update CORS document #​15784
  • Update eclipse/vscode configuration to use -parameters #​15680

❤️ Contributors

Thank you to all the contributors who worked on this release:

@​Junhyunny, @​dependabot[bot], @​github-actions[bot], @​hwanders, and @​ngocnhan-tran1996

v6.2.6

Compare Source

⭐ New Features

  • ActiveDirectoryLdapAuthenticationProvider does not implement support for multiple urls #​15494
  • Document the role of CredentialsContainer #​15320
  • OIDC Backchannel Logout should allow logout tokens having typ header of logout+jwt #​15277

🪲 Bug Fixes

  • A broken link in Spring Security reference #​15288
  • Correct HttpSessionCsrfTokenRepository Documentation #​15392
  • Documentation for ServletBearerExchangeFilterFunction incomplete or incorrect #​15459
  • Restrict automatic CORS configuration to UrlBasedCorsConfigurationSource #​15444
  • Update prerequisites documentation with Java 17 #​15323
  • Using sec:authorize in JSPX causes 'java.lang.NullPointerException: Cannot invoke "jakarta.servlet.ServletRegistration.getClassName()" because "registration" is null' #​15439

🔨 Dependency Upgrades

  • Bump com.github.spullara.mustache.java:compiler from 0.9.13 to 0.9.14 #​15376
  • Bump io.micrometer:micrometer-observation from 1.12.7 to 1.12.8 #​15381
  • Bump io.micrometer:micrometer-observation from 1.12.8 to 1.12.9 #​15588
  • Bump io.mockk:mockk from 1.13.11 to 1.13.12 #​15427
  • Bump io.projectreactor:reactor-bom from 2023.0.7 to 2023.0.8 #​15389
  • Bump io.projectreactor:reactor-bom from 2023.0.8 to 2023.0.9 #​15599
  • Bump jakarta.servlet.jsp.jstl:jakarta.servlet.jsp.jstl-api from 3.0.0 to 3.0.1 #​15589
  • Bump org-apache-maven-resolver from 1.9.20 to 1.9.21 #​15377
  • Bump org-apache-maven-resolver from 1.9.21 to 1.9.22 #​15543
  • Bump org-eclipse-jetty from 11.0.21 to 11.0.22 #​15358
  • Bump org.apache.maven:maven-resolver-provider from 3.9.7 to 3.9.8 #​15271
  • Bump org.apache.maven:maven-resolver-provider from 3.9.8 to 3.9.9 #​15645
  • Bump org.jetbrains.kotlin:kotlin-bom from 1.9.24 to 1.9.25 #​15452
  • Bump org.jetbrains.kotlin:kotlin-gradle-plugin from 1.9.24 to 1.9.25 #​15451
  • Bump org.junit:junit-bom from 5.10.2 to 5.10.3 #​15314
  • Bump org.skyscreamer:jsonassert from 1.5.1 to 1.5.3 #​15333
  • Bump org.slf4j:slf4j-api from 2.0.13 to 2.0.14 #​15528
  • Bump org.slf4j:slf4j-api from 2.0.14 to 2.0.15 #​15544
  • Bump org.slf4j:slf4j-api from 2.0.15 to 2.0.16 #​15570
  • Bump org.springframework.data:spring-data-bom from 2023.1.7 to 2023.1.8 #​15422
  • Bump org.springframework.data:spring-data-bom from 2023.1.8 to 2023.1.9 #​15644
  • Bump org.springframework.ldap:spring-ldap-core from 3.2.4 to 3.2.6 #​15618
  • Bump org.springframework:spring-framework-bom from 6.1.10 to 6.1.11 #​15404
  • Bump org.springframework:spring-framework-bom from 6.1.11 to 6.1.12 #​15614
  • Bump org.springframework:spring-framework-bom from 6.1.9 to 6.1.10 #​15280

🔩 Build Updates

  • Automate check of expected branch version #​15309
  • Bump @antora/collector-extension from 1.0.0-alpha.4 to 1.0.0-alpha.6 in /docs #​15445
  • Bump @antora/collector-extension from 1.0.0-alpha.6 to 1.0.0-alpha.7 in /docs #​15488
  • Bump @antora/collector-extension from 1.0.0-alpha.7 to 1.0.0-beta.1 in /docs #​15563
  • Bump @antora/collector-extension from 1.0.0-beta.1 to 1.0.0-beta.2 in /docs #​15639
  • Bump @springio/antora-extensions from 1.11.1 to 1.12.0 in /docs #​15415
  • Bump @springio/antora-extensions from 1.12.0 to 1.13.0 in /docs #​15516
  • Bump @springio/antora-extensions from 1.13.0 to 1.13.1 in /docs #​15562
  • Bump @springio/antora-extensions from 1.13.1 to 1.14.2 in /docs #​15638
  • Bump @springio/asciidoctor-extensions from 1.0.0-alpha.10 to 1.0.0-alpha.11 in /docs #​15414
  • Bump @springio/asciidoctor-extensions from 1.0.0-alpha.11 to 1.0.0-alpha.12 in /docs #​15518
  • Bump antora from 3.2.0-alpha.4 to 3.2.0-alpha.5 in /docs #​15328
  • Bump antora from 3.2.0-alpha.5 to 3.2.0-alpha.6 in /docs #​15489
  • Bump com.gradle.develocity from 3.17.5 to 3.17.6 #​15465
  • Bump io-spring-javaformat from 0.0.42 to 0.0.43 #​15649
  • Migrate slack notifications to GChat #​15504

❤️ Contributors

Thank you to all the contributors who worked on this release:

@​Junhyunny, @​Kehrlann, @​OLibutzki, @​arey, @​baezzys, and @​dependabot[bot]

v6.2.5

Compare Source

⭐ New Features

  • doc: added hint to declare GrantedAuthorityDefaults as infrastructure bean #​15063
  • Enhance Logging in RequestMatcherDelegatingAuthorizationManage #​14922
  • InMemoryUserDetailsManager: consider improving the error message when no PasswordEncoding has been specified #​14974
  • Mention all required dependencies in LDAP documentation #​15244

🪲 Bug Fixes

  • Assert WebSession is not null #​15178
  • AbstractRequestMatcherRegistry#requestMatchers should pick MvcRequestMatcher when using MockMvc #​15210
  • DispatcherServletDelegatingRequestMatcher causes errors when running tests with MockMvc #​15196
  • Fix Java example in multitenanci.adoc #​15150
  • Incorrect documentation for OIDC Back-Channel Logout #​15198
  • InMemoryUserDetailsManager Setting User Roles in Official Documentation Example Causes Error #​14972
  • LDIF file on official documentation breaks the startup process #​15166
  • Link to article with remember-me-persistent-token strategy is broken #​15148
  • OIDC Logout section is not shown in the navbar #​15112
  • OpenSaml4AssertionValidator is not respecting clock skew settings #​15022
  • ProxyRestrictionConditionValidator is missing in the OpenSaml4AuthenticationProvider.SAML20AssertionValidators class #​14958
  • Resolving invalid CSRF token values is not consistent #​15185
  • spring-security/docs/modules/ROOT/pages/servlet/authorization /method-security #​15045
  • Wrong information for RequestCacheAwareFilter in the Spring Security documentation. #​14995

🔨 Dependency Upgrades

  • Bump com.fasterxml.jackson:jackson-bom from 2.17.0 to 2.17.1 #​15011
  • Bump io.micrometer:micrometer-observation from 1.12.5 to 1.12.6 #​15069
  • Bump io.micrometer:micrometer-observation from 1.12.6 to 1.12.7 #​15224
  • Bump io.mockk:mockk from 1.13.10 to 1.13.11 #​15079
  • Bump io.projectreactor:reactor-bom from 2023.0.5 to 2023.0.6 #​15075
  • Bump io.projectreactor:reactor-bom from 2023.0.6 to 2023.0.7 #​15232
  • Bump org-apache-maven-resolver from 1.9.18 to 1.9.19 #​14939
  • Bump org-apache-maven-resolver from 1.9.19 to 1.9.20 #​15031
  • Bump org-aspectj from 1.9.22 to 1.9.22.1 #​15049
  • Bump org-eclipse-jetty from 11.0.20 to 11.0.21 #​15080
  • Bump org.apache.maven:maven-resolver-provider from 3.9.6 to 3.9.7 #​15170
  • Bump org.hibernate.orm:hibernate-core from 6.4.4.Final to 6.4.5.Final #​14949
  • Bump org.hibernate.orm:hibernate-core from 6.4.5.Final to 6.4.6.Final #​14953
  • Bump org.hibernate.orm:hibernate-core from 6.4.6.Final to 6.4.7.Final #​14960
  • Bump org.hibernate.orm:hibernate-core from 6.4.7.Final to 6.4.8.Final #​14981
  • Bump org.hsqldb:hsqldb from 2.7.2 to 2.7.3 #​15192
  • Bump org.jetbrains.kotlin:kotlin-bom from 1.9.23 to 1.9.24 #​15024
  • Bump org.jetbrains.kotlin:kotlin-gradle-plugin from 1.9.23 to 1.9.24 #​15023
  • Bump org.opensaml:opensaml-core4 from 4.3.1 to 4.3.2 #​14947
  • Bump org.springframework.data:spring-data-bom from 2023.1.5 to 2023.1.6 #​15101
  • Bump org.springframework.data:spring-data-bom from 2023.1.6 to 2023.1.7 #​15262
  • Bump org.springframework.ldap:spring-ldap-core from 3.2.3 to 3.2.4 #​15248
  • Bump org.springframework:spring-framework-bom from 6.1.6 to 6.1.7 #​15081
  • Bump org.springframework:spring-framework-bom from 6.1.7 to 6.1.8 #​15132
  • Bump org.springframework:spring-framework-bom from 6.1.8 to 6.1.9 #​15247
  • Update to OAuth2 OIDC SDK 9.43.4 #​14920
  • Upgrade nimbus-jose-jwt to version 9.37.3 #​14836

🔩 Build Updates

  • Attach Antora Docs to Pull Requests #​15060
  • Bump @antora/collector-extension from 1.0.0-alpha.3 to 1.0.0-alpha.4 in /docs #​15163
  • Bump @springio/antora-extensions from 1.10.0 to 1.11.1 in /docs #​15142
  • Bump com.github.spullara.mustache.java:compiler from 0.9.11 to 0.9.13 #​15032
  • Bump com.gradle.develocity from 3.17.2 to 3.17.3 #​15050
  • Bump com.gradle.develocity from 3.17.3 to 3.17.4 #​15102
  • Bump com.gradle.develocity from 3.17.4 to 3.17.5 #​15241
  • Bump io-spring-javaformat from 0.0.41 to 0.0.42 #​15216
  • Bump io.spring.ge.conventions from 0.0.16 to 0.0.17 #​14961
  • Bump io.spring.gradle:spring-security-release-plugin from 1.0.2 to 1.0.3 #​14924
  • Bump org.jfrog.buildinfo:build-info-extractor-gradle from 4.33.13 to 4.33.15 #​14950
  • Consider Adding a Build Updates section to the release changelog #​15038

❤️ Contributors

Thank you to all the contributors who worked on this release:

@​dependabot[bot]

v6.2.4

Compare Source

🪲 Bug Fixes

  • SpaCsrfTokenRequestHandler(Kotlin) documented in csrf-integration-javascript-spa causes NullPointerException #​14805
  • Address AuthorizationObservationConvention Package Tangle #​14795
  • bug org.springframework.security.oauth2.server.resource.introspection.SpringOpaqueTokenIntrospector introspect method error #​14848
  • Transactional annotation breaks AOT for native image #​14865

🔨 Dependency Upgrades

  • Bump io.micrometer:micrometer-observation from 1.12.4 to 1.12.5 #​14867
  • Bump io.projectreactor:reactor-bom from 2023.0.4 to 2023.0.5 #​14873
  • Bump io.spring.ge.conventions from 0.0.15 to 0.0.16 #​14821
  • Bump io.spring.gradle:spring-security-release-plugin from 1.0.1 to 1.0.2 #​14786
  • Bump org-aspectj from 1.9.21.2 to 1.9.22 #​14798
  • Bump org.slf4j:slf4j-api from 2.0.12 to 2.0.13 #​14907
  • Bump org.springframework.data:spring-data-bom from 2023.1.4 to 2023.1.5 #​14908
  • Bump org.springframework.ldap:spring-ldap-core from 3.2.2 to 3.2.3 #​14896
  • Bump org.springframework:spring-framework-bom from 6.1.5 to 6.1.6 #​14895
  • Update org.opensaml:opensaml-core4 to 4.3.1 #​14850

❤️ Contributors

Thank you to all the contributors who worked on this release:

@​dependabot[bot]

v6.2.3

Compare Source

⭐ New Features

  • Structure101 Plugin Should Ignore Deprecated Files #​14640

🪲 Bug Fixes

  • Check for null Authentication #​14666
  • Fix Package Tangle in CAS #​14641
  • LogoutConfigurer#createLogoutFilter sets the SecurityContextHolderStrategy twice #​14648
  • ObservationTextHandler class is not defined in a reactive context #​14653
  • PostAuthorize Method Interceptors Should Use Order from AuthorizationInterceptorsOrder #​14723
  • Spring security's ServerLogoutHandler order problem. #​14682

🔨 Dependency Upgrades

  • Bump io.micrometer:micrometer-observation from 1.12.3 to 1.12.4 #​14719
  • Bump io.mockk:mockk from 1.13.9 to 1.13.10 #​14661
  • Bump io.projectreactor:reactor-bom from 2023.0.3 to 2023.0.4 #​14726
  • Bump jakarta.xml.bind:jakarta.xml.bind-api from 4.0.1 to 4.0.2 #​14705
  • Bump org-aspectj from 1.9.21.1 to 1.9.21.2 #​14734
  • Bump org.jetbrains.kotlin:kotlin-bom from 1.9.22 to 1.9.23 #​14706
  • Bump org.jetbrains.kotlin:kotlin-gradle-plugin from 1.9.22 to 1.9.23 #​14704
  • Bump org.springframework.data:spring-data-bom from 2023.1.3 to 2023.1.4 #​14770
  • Bump org.springframework:spring-framework-bom from 6.1.4 to 6.1.5 #​14757

❤️ Contributors

Thank you to all the contributors who worked on this release:

@​dependabot[bot]

[v6.2.2](https://redirect.github.com/spring-projects/spring-security/releases/tag/6.2.2


Configuration

📅 Schedule: Branch creation - "after 7am and before 11am every weekday" in timezone Europe/London, Automerge - At any time (no schedule defined).

🚦 Automerge: Disabled by config. Please merge this manually once you are satisfied.

Rebasing: Whenever PR is behind base branch, or you tick the rebase/retry checkbox.

🔕 Ignore: Close this PR and you won't be reminded about this update again.


  • If you want to rebase/retry this PR, check this box

This PR was generated by Mend Renovate. View the repository job log.

@renovate renovate bot force-pushed the renovate/major-spring-security branch from 6496827 to ce3edfe Compare November 20, 2023 18:28
@renovate renovate bot force-pushed the renovate/major-spring-security branch from ce3edfe to 70dadf0 Compare December 18, 2023 19:32
@renovate renovate bot force-pushed the renovate/major-spring-security branch from 70dadf0 to d57029d Compare February 13, 2024 11:32
@renovate renovate bot force-pushed the renovate/major-spring-security branch from d57029d to 39a57f8 Compare February 16, 2024 21:25
@renovate renovate bot force-pushed the renovate/major-spring-security branch from 39a57f8 to 3518d88 Compare March 18, 2024 15:09
@renovate renovate bot force-pushed the renovate/major-spring-security branch from 3518d88 to 2234bf1 Compare April 15, 2024 20:40
@renovate renovate bot force-pushed the renovate/major-spring-security branch from 2234bf1 to e2a6e1e Compare April 24, 2024 09:57
@renovate renovate bot force-pushed the renovate/major-spring-security branch from e2a6e1e to 6ec1767 Compare May 20, 2024 20:06
@renovate renovate bot force-pushed the renovate/major-spring-security branch from 6ec1767 to 8eddd05 Compare June 17, 2024 18:01
@renovate renovate bot force-pushed the renovate/major-spring-security branch from 8eddd05 to dbd6219 Compare August 19, 2024 22:14
@hmcts-jenkins-d-to-i hmcts-jenkins-d-to-i bot requested a deployment to preview August 19, 2024 22:22 Abandoned
@renovate renovate bot force-pushed the renovate/major-spring-security branch from dbd6219 to 2baf1c8 Compare August 21, 2024 17:37
@hmcts-jenkins-d-to-i hmcts-jenkins-d-to-i bot requested a deployment to preview August 21, 2024 17:47 Abandoned
@renovate renovate bot force-pushed the renovate/major-spring-security branch from 2baf1c8 to 331252b Compare October 21, 2024 18:34
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
dependencies Pull requests that update a dependency file ns:divorce prd:div rel:div-cms-pr-776
Projects
None yet
Development

Successfully merging this pull request may close these issues.

1 participant