Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

fix(deps): update spring security to v6.4.4 #84

Merged
merged 5 commits into from
Apr 3, 2025

Conversation

renovate[bot]
Copy link
Contributor

@renovate renovate bot commented Feb 28, 2025

This PR contains the following updates:

Package Change Age Adoption Passing Confidence
org.springframework.security:spring-security-oauth2-resource-server (source) 6.3.0 -> 6.4.4 age adoption passing confidence
org.springframework.security:spring-security-oauth2-jose (source) 6.3.0 -> 6.4.4 age adoption passing confidence
org.springframework.security:spring-security-oauth2-client (source) 6.3.0 -> 6.4.4 age adoption passing confidence

Release Notes

spring-projects/spring-security (org.springframework.security:spring-security-oauth2-resource-server)

v6.4.4

Compare Source

🪲 Bug Fixes

  • Add testRuntimeOnly junit-platform-launcher #​16756
  • Align Method Traversal Algorithm with Spring Framework #​16751
  • Disable Flaky WebAuthnWebDriverTests #​16753
  • Fix @PostResult example in method-security doc #​16628
  • Grammar Fixes in OAuth 2.0 JavaDoc #​16619

🔨 Dependency Upgrades

  • Bump ch.qos.logback:logback-classic from 1.5.16 to 1.5.17 #​16649
  • Bump com.fasterxml.jackson:jackson-bom from 2.18.2 to 2.18.3 #​16692
  • Bump com.webauthn4j:webauthn4j-core from 0.28.5.RELEASE to 0.28.6.RELEASE #​16691
  • Bump io.micrometer:micrometer-observation from 1.14.4 to 1.14.5 #​16715
  • Bump io.mockk:mockk from 1.13.16 to 1.13.17 #​16675
  • Bump io.projectreactor:reactor-bom from 2023.0.15 to 2023.0.16 #​16725
  • Bump org.hibernate.orm:hibernate-core from 6.6.10.Final to 6.6.11.Final #​16748
  • Bump org.jfrog.buildinfo:build-info-extractor-gradle from 4.33.23 to 4.33.24 #​16669
  • Bump org.slf4j:slf4j-api from 2.0.16 to 2.0.17 #​16650
  • Bump org.springframework.data:spring-data-bom from 2024.1.3 to 2024.1.4 #​16749
  • Bump org.springframework:spring-framework-bom from 6.2.3 to 6.2.4 #​16733

❤️ Contributors

Thank you to all the contributors who worked on this release:

@​Kuba15, @​dependabot[bot], and @​pat-mccusker

v6.4.3

Compare Source

⭐ New Features
  • Add Support disableDefaultRegistrationPage to WebAuthnDsl #​16395
🪲 Bug Fixes
  • withValue used incorrectly #​16527
  • Fix for JdbcOneTimeTokenService cleanupExpiredTokens failing with PostgreSQL #​16344
  • Fix GenerateOneTimeTokenWebFilter double publish of chain.filter(...) #​16459
  • Fix Kotlin DSL webAuthn { } #​16338
  • Fix loader has changed while resolving nodes in WebAuthnWebDriverTests #​16463
  • Fix logoutRequestRepository not set on Saml2RelyingPartyInitiatedLogoutSuccessHandler #​16310
  • Implement Serializable for WebAuthnAuthentication #​16285
  • Make AuthorizationDecision Serializable #​16544
  • Make PublicKeyCredentialRequestOptions Serializable Backport #​16584
  • Make Saml2AuthenticationToken Serializable #​16287
  • Make WebAuthnAuthentication Serializable #​16273
  • Make WebAuthnAuthenticationRequestToken Serializable #​16602
  • Make WebAuthnAuthenticationTokenRequest Serializable #​16481
  • Misconfigured OAuth2LoginAuthenticationFilter when combining OAuth2 login and OAuth2 client configuration #​16466
  • OTT Should Use non-static member to capture the last OneTimeToken #​16471
  • webauthn js should ensure allowCredentials[].id is an ArrayBuffer #​16440
🔨 Dependency Upgrades
  • Bump ch.qos.logback:logback-classic from 1.5.15 to 1.5.16 #​16364
  • Bump com.nimbusds:oauth2-oidc-sdk from 9.43.5 to 9.43.6 #​16598
  • Bump com.webauthn4j:webauthn4j-core from 0.28.4.RELEASE to 0.28.5.RELEASE #​16523
  • Bump io.micrometer:micrometer-observation from 1.14.3 to 1.14.4 #​16565
  • Bump io.mockk:mockk from 1.13.14 to 1.13.16 #​16399
  • Bump io.projectreactor:reactor-bom from 2023.0.14 to 2023.0.15 #​16576
  • Bump io.rsocket:rsocket-bom from 1.1.4 to 1.1.5 #​16534
  • Bump org.hibernate.orm:hibernate-core from 6.6.7.Final to 6.6.8.Final #​16610
  • Bump org.junit:junit-bom from 5.11.3 to 5.11.4 #​16292
  • Bump org.springframework.data:spring-data-bom from 2024.1.2 to 2024.1.3 #​16611
  • Bump org.springframework.ldap:spring-ldap-core from 3.2.10 to 3.2.11 #​16597
  • Bump org.springframework:spring-framework-bom from 6.2.2 to 6.2.3 #​16599
  • Update to oauth2-oidc-sdk 9.43.5 #​16583
🔩 Build Updates
❤️ Contributors

Thank you to all the contributors who worked on this release:

@​Kehrlann, @​NeoTraveler, @​dependabot[bot], @​franticticktick, @​making, and @​ngocnhan-tran1996

v6.4.2

Compare Source

⭐ New Features
  • Add 6.4 Sample Serializations for Serializable classes #​16274
  • Add @inheritDoc to sessionIdChanged method #​16216
  • Fix typo in oauth2 resource server documentation #​16053
  • Fixed confusing phrasing in the docs for a better clarity. #​16169
  • Improve AuthorizationManager configuration error messages #​16194
  • Polish #​16148
  • Use Documentation Tags for Maven and Gradle in Getting Started #​16234
  • Add WebDriver WebAuthn test #​15969
🪲 Bug Fixes
  • Add Deprecated ObjectPostProcessor constructor #​16212
  • Add RuntimeHints for webauthn Javascript resource #​16159
  • Always return current ClientRegistration in loadAuthorizedClient #​16139
  • Avoid requesting an unnecessary attestation statement when creating a webauthn credential #​16252
  • CI is not using the correct secret for Develocity #​16263
  • Dark mode rendering issue with images on CSRF and Method Security pages #​16176
  • DefaultSaml2AuthenticatedPrincipal should define a serialVersionUID #​16163
  • Delay initialization of AuthenticationProvider in Global Authentication #​16147
  • Fix Documentation Typos #​16054
  • Correct OAuth2ClientHttpRequestInterceptor Usage Documentation #​16172
  • Fix Typo in 'What's New' Documentation #​16183
  • Fix WebAuthnWebdriverTests #​16279
  • Correct OpenSAML 5.x Documentation #​16195
  • Issue when using @AuthenticationPrincipal on interfaces #​16177
  • Mutate breaks functionality of StrictFirewallHttpHeaders with recently modified HttpHeaders#writabeHttpHeaders #​16261
  • Remove duplicate cache in AuthenticationPrincipalArgumentResolverand CurrentSecurityContextArgumentResolver #​16202
  • Resolve ObjectPostProcessor collisions between RSocket and WebFlux security configuration #​16161
  • Restore @AuthenticationPrincipal/@CurrentSecurityContext Interface Support #​16245
  • Restore Servlet 5 Compatiblity for CookieCsrfTokenRepository #​16220
  • Spelling error in opensaml.adoc #​16146
  • Update document regarding PublicKeyCredentialCreationOptions.attestation value #​16264
  • Verification Options Should Return Saved Transports for Credentials #​16084
🔨 Dependency Upgrades
  • Bump com.fasterxml.jackson:jackson-bom from 2.18.1 to 2.18.2 #​16184
  • Bump com.webauthn4j:webauthn4j-core from 0.28.2.RELEASE to 0.28.3.RELEASE #​16203
  • Bump io.micrometer:micrometer-observation from 1.14.1 to 1.14.2 #​16255
  • Bump io.projectreactor:reactor-bom from 2023.0.12 to 2023.0.13 #​16256
  • Bump org.gradle.wrapper-upgrade from 0.11.4 to 0.12 #​16209
  • Bump org.gretty:gretty from 4.1.5 to 4.1.6 #​16247
  • Bump org.hibernate.orm:hibernate-core from 6.6.2.Final to 6.6.3.Final #​16145
  • Bump org.htmlunit:htmlunit from 4.6.0 to 4.7.0 #​16205
  • Bump org.jfrog.buildinfo:build-info-extractor-gradle from 4.33.22 to 4.33.23 #​16180
  • Bump org.seleniumhq.selenium:htmlunit3-driver from 4.26.0 to 4.27.0 #​16204
  • Bump org.seleniumhq.selenium:selenium-java from 4.26.0 to 4.27.0 #​16167
  • Bump org.springframework.data:spring-data-bom from 2024.1.0 to 2024.1.1 #​16290
  • Bump org.springframework.ldap:spring-ldap-core from 3.2.8 to 3.2.10 #​16270
  • Bump org.springframework:spring-framework-bom from 6.2.0 to 6.2.1 #​16271
🔩 Build Updates
  • Bump @antora/collector-extension from 1.0.0 to 1.0.1 in /docs #​16239
  • Bump antora from 3.2.0-alpha.6 to 3.2.0-alpha.8 in /docs #​16237
  • Bump gradle/gradle-build-action from 2 to 3 #​16278
  • Remove 5.8.x and 6.2.x dependabot configuration #​16268
  • Remove 5.8.x from Auto Merge Forward Dependabot PRs #​15770
❤️ Contributors

Thank you to all the contributors who worked on this release:

@​12OneTwo12, @​Kehrlann, @​MuhammadNFadhil, @​OrangeDog, @​Spikhalskiy, @​dependabot[bot], @​harpreets789, @​kse-music, @​martin-tarjanyi, @​ngocnhan-tran1996, and @​ynojima

v6.4.1

Compare Source

🪲 Bug Fixes
  • Documentation images should render clearly in both light and dark mode #​16132
  • Fix conflicting bean names between @EnableWebSecurity and @EnableWebSocketSecurity #​16113
🔩 Build Updates
  • Update Antora UI Spring to v0.4.18 #​16112
❤️ Contributors

Thank you to all the contributors who worked on this release:

@​github-actions[bot] and @​ngocnhan-tran1996

v6.4.0

Compare Source

⭐ New Features
  • Add @FunctionalInterface to AuthorizationEventPublisher #​15934
  • Add DefaultResourcesFilter.webauthn() #​15970
  • Add deprecation notice for missing leading slashes #​16020
  • Code Cleanup #​15996
  • Document passkeys dependencies #​16107
  • Factor out some common object mocking in tests #​15396
  • Fix saml2 authentication guide docs #​16017
  • Improve documentation about CredentialsContainer #​15554
  • Improve Documentation on Adding a Custom Security Filter #​15893
  • Improve Error Message for Conflicting Filter Chains #​15992
  • Make it easier to determine where a filter chain has been defined #​15874
  • OIDC logout not working for JPA/JDBC OAuth2AuthorizationService because DefaultSaml2AuthenticatedPrincipal does not implement equality #​15346
  • Polish JdbcOneTimeTokenService #​15997
  • relying-party-registration doesn't allow placeholders in xml #​14645
  • Remove unnecessary parentheses and add static final field MockPortResolver#getServerPort #​15875
  • Support ServerExchangeRejectedHandler @Bean #​16063
🪲 Bug Fixes
  • An empty-string bearer token should result in an appropriate HTTP status code #​16037
  • AuthorizeReturnObject AOT support should register proxied class as well #​16106
  • Correct class name reference in WebFilterChainProxy JavaDoc #​16004
  • Fix typo javadoc some classes #​16022
  • Initialize OpenSAML in OpenSamlAssertingPartyMetadataRepository #​16055
  • IpAddressMatcher null pointer exception #​16104
  • OpenSamlAssertingPartyMetadataRepository should initialize OpenSAML #​16042
  • Support ServerWebExchangeFirewall @Bean #​15999
  • UniqueSecurityAnnotationScanner throws ConcurrentModificationException #​15906
🔨 Dependency Upgrades
  • Bump ch.qos.logback:logback-classic from 1.5.11 to 1.5.12 #​16005
  • Bump com.fasterxml.jackson:jackson-bom from 2.18.0 to 2.18.1 #​16007
  • Bump com.webauthn4j:webauthn4j-core from 0.28.1.RELEASE to 0.28.2.RELEASE #​16122
  • Bump io.freefair.gradle:aspectj-plugin from 8.10.2 to 8.11 #​16123
  • Bump io.micrometer:micrometer-observation from 1.14.0 to 1.14.1 #​16121
  • Bump io.projectreactor:reactor-bom from 2023.0.11 to 2023.0.12 #​16079
  • Bump org-bouncycastle from 1.78.1 to 1.79 #​16010
  • Bump org.hibernate.orm:hibernate-core from 6.6.1.Final to 6.6.2.Final #​16048
  • Bump org.hsqldb:hsqldb from 2.7.3 to 2.7.4 #​16028
  • Bump org.htmlunit:htmlunit from 4.5.0 to 4.6.0 #​16044
  • Bump org.junit:junit-bom from 5.11.2 to 5.11.3 #​15968
  • Bump org.seleniumhq.selenium:htmlunit3-driver from 4.25.0 to 4.26.0 #​16043
  • Bump org.seleniumhq.selenium:selenium-java from 4.25.0 to 4.26.0 #​16018
  • Bump org.springframework.data:spring-data-bom from 2024.0.5 to 2024.1.0 #​16124
  • Bump org.springframework.ldap:spring-ldap-core from 3.2.7 to 3.2.8 #​16097
  • Bump org.springframework:spring-framework-bom from 6.2.0-RC3 to 6.2.0 #​16096
🔩 Build Updates
  • Bump @antora/collector-extension from 1.0.0-beta.4 to 1.0.0-beta.5 in /docs #​16115
  • Update Antora UI Spring to v0.4.17 #​15929
❤️ Contributors

Thank you to all the contributors who worked on this release:

@​Chu3laMan, @​Kehrlann, @​Limm-jk, @​dcolazin, @​dependabot[bot], @​franticticktick, @​github-actions[bot], @​gzhao9, @​ig-jinwoo, @​jzheaux, @​kse-music, @​ngocnhan-tran1996, and @​nomoreFt

v6.3.8

Compare Source

🪲 Bug Fixes
  • Add testRuntimeOnly junit-platform-launcher #​16755
  • Fix typo security-api-url attribute in faq.adoc #​16633
  • Security SpEL Expressions Should Propagate AuthorizationDeniedException from Proxied Objects #​16697
🔨 Dependency Upgrades
  • Bump ch.qos.logback:logback-classic from 1.5.16 to 1.5.17 #​16651
  • Bump io.mockk:mockk from 1.13.16 to 1.13.17 #​16676
  • Bump io.projectreactor:reactor-bom from 2023.0.15 to 2023.0.16 #​16724
  • Bump org.jfrog.buildinfo:build-info-extractor-gradle from 4.33.23 to 4.33.24 #​16670
  • Bump org.slf4j:slf4j-api from 2.0.16 to 2.0.17 #​16652
  • Bump org.springframework.data:spring-data-bom from 2024.0.9 to 2024.0.10 #​16747
  • Bump org.springframework:spring-framework-bom from 6.1.17 to 6.1.18 #​16735
🔩 Build Updates
  • Bump @springio/antora-extensions from 1.14.2 to 1.14.4 in /docs #​16637
❤️ Contributors

Thank you to all the contributors who worked on this release:

@​dependabot[bot] and @​ngocnhan-tran1996

v6.3.7

Compare Source

⭐ New Features
  • Improve Stability of S101 CI Task #​16482
🪲 Bug Fixes
  • Fix logoutRequestRepository not set on Saml2RelyingPartyInitiatedLogoutSuccessHandler #​16093
  • Misconfigured OAuth2LoginAuthenticationFilter when combining OAuth2 login and OAuth2 client configuration #​16105
🔨 Dependency Upgrades
  • Bump ch.qos.logback:logback-classic from 1.5.15 to 1.5.16 #​16363
  • Bump com.nimbusds:oauth2-oidc-sdk from 9.43.5 to 9.43.6 #​16594
  • Bump io.mockk:mockk from 1.13.14 to 1.13.16 #​16400
  • Bump io.projectreactor:reactor-bom from 2023.0.14 to 2023.0.15 #​16577
  • Bump io.rsocket:rsocket-bom from 1.1.4 to 1.1.5 #​16533
  • Bump org.springframework.data:spring-data-bom from 2024.0.8 to 2024.0.9 #​16607
  • Bump org.springframework.ldap:spring-ldap-core from 3.2.10 to 3.2.11 #​16595
  • Bump org.springframework:spring-framework-bom from 6.1.16 to 6.1.17 #​16596
  • Update to oauth2-oidc-sdk 9.43.5 #​16582
🔩 Build Updates
  • Bump @springio/asciidoctor-extensions from 1.0.0-alpha.14 to 1.0.0-alpha.16 in /docs #​16519
  • Troubleshoot missing GChat notifications #​16423
❤️ Contributors

Thank you to all the contributors who worked on this release:

@​dependabot[bot] and @​sawprogramming

v6.3.6

Compare Source

🪲 Bug Fixes
  • Always return current ClientRegistration in loadAuthorizedClient #​16138
  • CI is not using the correct secret for Develocity #​16262
  • Dark mode rendering issue with images on CSRF and Method Security pages #​16175
  • Delay initialization AuthenticationProvider in Global Authentication #​16050
  • Do not eagerly construct UserDetailsService bean in Global Authentication #​16144
  • Documentation images should render clearly in both light and dark mode #​16131
  • Mutate breaks functionality of StrictFirewallHttpHeaders with recently modified HttpHeaders#writabeHttpHeaders #​16069
  • OidcBackChannelLogoutWebFilter error response is not a correct JSON #​16229
  • Restore Servlet 5 Compatiblity for CookieCsrfTokenRepository #​16219
🔨 Dependency Upgrades
  • Bump io.projectreactor:reactor-bom from 2023.0.12 to 2023.0.13 #​16257
  • Bump org.gretty:gretty from 4.1.5 to 4.1.6 #​16246
  • Bump org.jfrog.buildinfo:build-info-extractor-gradle from 4.33.22 to 4.33.23 #​16179
  • Bump org.springframework.data:spring-data-bom from 2024.0.6 to 2024.0.7 #​16289
  • Bump org.springframework.ldap:spring-ldap-core from 3.2.8 to 3.2.10 #​16269
  • Bump org.springframework:spring-framework-bom from 6.1.15 to 6.1.16 #​16272
🔩 Build Updates
  • Bump antora from 3.2.0-alpha.6 to 3.2.0-alpha.8 in /docs #​16244
  • Update Antora UI Spring to v0.4.18 #​16110
❤️ Contributors

Thank you to all the contributors who worked on this release:

@​dependabot[bot], @​github-actions[bot], and @​kse-music

v6.3.5

Compare Source

⭐ New Features
  • Support ServerExchangeRejectedHandler @Bean #​16062
  • Supporting logout+jwt for back-channel logout with spring-webflux #​15702
🪲 Bug Fixes
  • Align DelegatingAuthenticationConverter Constructors #​15949
  • An empty-string bearer token should result in an appropriate HTTP status code #​16036
  • IpAddressMatcher null pointer exception #​15527
  • RequestMatcherDelegatingAuthorizationManager should be post-processable #​15981
  • Support ServerWebExchangeFirewall @Bean #​15991
  • Unhandled exception in CookieRequestCache results in 500 Internal Server Error #​15986
  • Update logout.adoc: Fix Customizing Logout Success Example #​15956
🔨 Dependency Upgrades
  • Bump ch.qos.logback:logback-classic from 1.5.11 to 1.5.12 #​16006
  • Bump com.fasterxml.jackson:jackson-bom from 2.17.2 to 2.17.3 #​16032
  • Bump io.micrometer:micrometer-observation from 1.12.12 to 1.12.13 #​16126
  • Bump io.projectreactor:reactor-bom from 2023.0.11 to 2023.0.12 #​16082
  • Bump org.hsqldb:hsqldb from 2.7.3 to 2.7.4 #​16033
  • Bump org.springframework.data:spring-data-bom from 2024.0.5 to 2024.0.6 #​16125
  • Bump org.springframework.ldap:spring-ldap-core from 3.2.7 to 3.2.8 #​16102
  • Bump org.springframework:spring-framework-bom from 6.1.14 to 6.1.15 #​16101
🔩 Build Updates
  • Bump @antora/collector-extension from 1.0.0-beta.4 to 1.0.0-beta.5 in /docs #​16117
  • Update Antora UI Spring to v0.4.17 #​15930
❤️ Contributors

Thank you to all the contributors who worked on this release:

@​asimuleo, @​dependabot[bot], @​github-actions[bot], and @​kse-music

v6.3.4

Compare Source

🪲 Bug Fixes
  • Annotation expression template processing should not fail on Class parameter types #​15711
  • Disabling credentials erasure on custom AuthenticationManager is not working #​15808
  • Documentation inconsistency in AuthorizationManager's verify method return type #​15822
  • Methods annotated with @PostFilter are processed twice by PostFilterAuthorizationMethodInterceptor #​15676
  • OidcBackChannelLogoutTokenValidator should not construct when missing OIDC Provider Issuer #​15868
  • SecurityJackson2Modules.getModules(): Cannot load module org.springframework.security.cas.jackson2.CasJackson2Module #​15767
  • The additionalParameters array parameter of OAuth2AuthorizationRequest causes the authorizationRequestUri to be incorrect #​15829
🔨 Dependency Upgrades
  • Bump ch.qos.logback:logback-classic from 1.5.10 to 1.5.11 #​15926
  • Bump io.micrometer:micrometer-observation from 1.12.10 to 1.12.11 #​15917
  • Bump io.mockk:mockk from 1.13.12 to 1.13.13 #​15897
  • Bump io.projectreactor:reactor-bom from 2023.0.10 to 2023.0.11 #​15925
  • Bump jakarta.servlet.jsp.jstl:jakarta.servlet.jsp.jstl-api from 3.0.1 to 3.0.2 #​15694
  • Bump org-eclipse-jetty from 11.0.23 to 11.0.24 #​15731
  • Bump org.jfrog.buildinfo:build-info-extractor-gradle from 4.33.21 to 4.33.22 #​15761
  • Bump org.junit:junit-bom from 5.10.4 to 5.10.5 #​15883
  • Bump org.springframework.data:spring-data-bom from 2024.0.4 to 2024.0.5 #​15958
  • Bump org.springframework.ldap:spring-ldap-core from 3.2.6 to 3.2.7 #​15944
  • Bump org.springframework:spring-framework-bom from 6.1.13 to 6.1.14 #​15945
🔩 Build Updates
  • Bump @antora/collector-extension from 1.0.0-beta.2 to 1.0.0-beta.3 in /docs #​15907
  • Bump @springio/asciidoctor-extensions from 1.0.0-alpha.13 to 1.0.0-alpha.14 in /docs #​15836
  • Migrate slack notifications to GChat #​15668
  • Release 6.3.4 #​15964
  • Update eclipse/vscode configuration to use -parameters #​15681
❤️ Contributors

Thank you to all the contributors who worked on this release:

@​dependabot[bot] and @​kse-music

v6.3.3

Compare Source

🪲 Bug Fixes
  • ObservationRegistry is never post-processed #​15658
🔨 Dependency Upgrades
  • Bump org-eclipse-jetty from 11.0.22 to 11.0.23 #​15664
❤️ Contributors

Thank you to all the contributors who worked on this release:

@​dependabot[bot]

v6.3.2

Compare Source

⭐ New Features
  • ActiveDirectoryLdapAuthenticationProvider does not implement support for multiple urls #​15495
  • Document the role of CredentialsContainer #​15321
  • OIDC Backchannel Logout should allow logout tokens having typ header of logout+jwt #​15410
🪲 Bug Fixes
  • A broken link in Spring Security reference #​15297
  • Documentation for ServletBearerExchangeFilterFunction incomplete or incorrect #​15460
  • EnableMethodSecurity should publish only one bean of each AuthorizationAdvisor #​15592
  • Fix Compromised Password Checker Docs Sample Not Working #​15305
  • Fix for #​15172 introduces significant performance degredation #​15324
  • Pre/PostAuthorize should not ignore HandleAuthorizationDenied#handlerClass when ApplicationContext is not provided #​15535
  • Update prerequisites documentation with Java 17 #​15340
  • Use Correct Meta-Annotation in Kotlin Sample #​15472
  • Using sec:authorize in JSPX causes 'java.lang.NullPointerException: Cannot invoke "jakarta.servlet.ServletRegistration.getClassName()" because "registration" is null' #​15440
🔨 Dependency Upgrades
  • Bump ch.qos.logback:logback-classic from 1.5.6 to 1.5.7 #​15619
  • Bump com.fasterxml.jackson:jackson-bom from 2.17.1 to 2.17.2 #​15374
  • Bump com.github.spullara.mustache.java:compiler from 0.9.13 to 0.9.14 #​15373
  • Bump io.micrometer:micrometer-observation from 1.12.7 to 1.12.8 #​15383
  • Bump io.micrometer:micrometer-observation from 1.12.8 to 1.12.9 #​15581
  • Bump io.mockk:mockk from 1.13.11 to 1.13.12 #​15430
  • Bump io.projectreactor:reactor-bom from 2023.0.7 to 2023.0.8 #​15388
  • Bump io.projectreactor:reactor-bom from 2023.0.8 to 2023.0.9 #​15597
  • Bump jakarta.servlet.jsp.jstl:jakarta.servlet.jsp.jstl-api from 3.0.0 to 3.0.1 #​15582
  • Bump org-apache-maven-resolver from 1.9.20 to 1.9.21 #​15372
  • Bump org-apache-maven-resolver from 1.9.21 to 1.9.22 #​15545
  • Bump org-eclipse-jetty from 11.0.21 to 11.0.22 #​15356
  • Bump org.apache.maven:maven-resolver-provider from 3.9.7 to 3.9.8 #​15268
  • Bump org.apache.maven:maven-resolver-provider from 3.9.8 to 3.9.9 #​15642
  • Bump org.gretty:gretty from 4.1.4 to 4.1.5 #​15431
  • Bump org.hibernate.orm:hibernate-core from 6.4.9.Final to 6.4.10.Final #​15530
  • Bump org.jetbrains.kotlin:kotlin-bom from 1.9.24 to 1.9.25 #​15456
  • Bump org.jetbrains.kotlin:kotlin-gradle-plugin from 1.9.24 to 1.9.25 #​15455
  • Bump org.jfrog.buildinfo:build-info-extractor-gradle from 4.33.19 to 4.33.20 #​15267
  • Bump org.junit:junit-bom from 5.10.2 to 5.10.3 #​15315
  • Bump org.skyscreamer:jsonassert from 1.5.1 to 1.5.3 #​15336
  • Bump org.slf4j:slf4j-api from 2.0.13 to 2.0.14 #​15529
  • Bump org.slf4j:slf4j-api from 2.0.14 to 2.0.15 #​15546
  • Bump org.slf4j:slf4j-api from 2.0.15 to 2.0.16 #​15571
  • Bump org.springframework.data:spring-data-bom from 2024.0.1 to 2024.0.2 #​15421
  • Bump org.springframework.data:spring-data-bom from 2024.0.2 to 2024.0.3 #​15643
  • Bump org.springframework.ldap:spring-ldap-core from 3.2.4 to 3.2.6 #​15620
  • Bump org.springframework:spring-framework-bom from 6.1.10 to 6.1.11 #​15402
  • Bump org.springframework:spring-framework-bom from 6.1.11 to 6.1.12 #​15613
  • Bump org.springframework:spring-framework-bom from 6.1.9 to 6.1.10 #​15279
🔩 Build Updates
  • Automate check of expected branch version #​15310
  • Bump @antora/collector-extension from 1.0.0-alpha.4 to 1.0.0-alpha.6 in /docs #​15449
  • Bump @antora/collector-extension from 1.0.0-alpha.6 to 1.0.0-alpha.7 in /docs #​15482
  • Bump @antora/collector-extension from 1.0.0-alpha.7 to 1.0.0-beta.1 in /docs #​15560
  • Bump @antora/collector-extension from 1.0.0-beta.1 to 1.0.0-beta.2 in /docs #​15637
  • Bump @springio/antora-extensions from 1.11.1 to 1.12.0 in /docs #​15418
  • Bump @springio/antora-extensions from 1.12.0 to 1.13.0 in /docs #​15517
  • Bump @springio/antora-extensions from 1.13.0 to 1.13.1 in /docs #​15561
  • Bump @springio/antora-extensions from 1.13.1 to 1.14.2 in /docs #​15636
  • Bump @springio/asciidoctor-extensions from 1.0.0-alpha.10 to 1.0.0-alpha.11 in /docs #​15419
  • Bump @springio/asciidoctor-extensions from 1.0.0-alpha.11 to 1.0.0-alpha.12 in /docs #​15515
  • Bump antora from 3.2.0-alpha.4 to 3.2.0-alpha.5 in /docs #​15329
  • Bump antora from 3.2.0-alpha.5 to 3.2.0-alpha.6 in /docs #​15480
  • Bump com.gradle.develocity from 3.17.5 to 3.17.6 #​15464
  • Bump io-spring-javaformat from 0.0.42 to 0.0.43 #​15650
  • Fix typos and formatting in documentation #​15380
  • Migrate slack notifications to GChat #​15505
  • Use explicit types instead of var #​15537
❤️ Contributors

Thank you to all the contributors who worked on this release:

@​Kehrlann, @​dependabot[bot], and @​tahakorkem

v6.3.1

Compare Source

⭐ New Features

  • Clarify the behavior of Concurrent Session Management when an IdP is involved #​15071
  • Mention all required dependencies in LDAP documentation #​15245
  • Minor docs fix #​15144

🪲 Bug Fixes

  • AbstractRequestMatcherRegistry#requestMatchers should pick MvcRequestMatcher when using MockMvc #​15211
  • Assert WebSession is not null #​15179
  • DispatcherServletDelegatingRequestMatcher causes errors when running tests with MockMvc #​15197
  • Documentation clarification after #​12783 has been closed is needed. #​15208
  • Fix Java example in multitenanci.adoc #​15151
  • Fix Kotlin example in authorize-http-requests.adoc #​15129
  • Incorrect documentation for OIDC Back-Channel Logout #​15212
  • IpAddressMatcher.matches(String address) still accepts URLs #​15172
  • LDIF file on official documentation breaks the startup process #​15167
  • Link to article with remember-me-persistent-token strategy is broken #​15149
  • OpenSaml4AssertionValidator is not respecting clock skew settings #​15183
  • Resolving invalid CSRF token values is not consistent #​15186
  • spring-security/docs/modules/ROOT/pages/servlet/authorization /method-security #​15143
  • SpringOpaqueTokenIntrospector does not add scopes as granted authorities properly #​15165

🔨 Dependency Upgrades

  • Bump io.micrometer:micrometer-observation from 1.12.6 to 1.12.7 #​15225
  • Bump io.projectreactor:reactor-bo

Configuration

📅 Schedule: Branch creation - At any time (no schedule defined), Automerge - At any time (no schedule defined).

🚦 Automerge: Disabled by config. Please merge this manually once you are satisfied.

Rebasing: Whenever PR becomes conflicted, or you tick the rebase/retry checkbox.

🔕 Ignore: Close this PR and you won't be reminded about these updates again.


  • If you want to rebase/retry this PR, check this box

This PR was generated by Mend Renovate. View the repository job log.

Copy link
Contributor

coderabbitai bot commented Feb 28, 2025

Important

Review skipped

Bot user detected.

To trigger a single review, invoke the @coderabbitai review command.

You can disable this status message by setting the reviews.review_status to false in the CodeRabbit configuration file.


Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out.

❤️ Share
🪧 Tips

Chat

There are 3 ways to chat with CodeRabbit:

  • Review comments: Directly reply to a review comment made by CodeRabbit. Example:
    • I pushed a fix in commit <commit_id>, please review it.
    • Generate unit testing code for this file.
    • Open a follow-up GitHub issue for this discussion.
  • Files and specific lines of code (under the "Files changed" tab): Tag @coderabbitai in a new review comment at the desired location with your query. Examples:
    • @coderabbitai generate unit testing code for this file.
    • @coderabbitai modularize this function.
  • PR comments: Tag @coderabbitai in a new PR comment to ask questions about the PR branch. For the best results, please provide a very specific query, as very limited context is provided in this mode. Examples:
    • @coderabbitai gather interesting stats about this repository and render them as a table. Additionally, render a pie chart showing the language distribution in the codebase.
    • @coderabbitai read src/utils.ts and generate unit testing code.
    • @coderabbitai read the files in the src/scheduler package and generate a class diagram using mermaid and a README in the markdown format.
    • @coderabbitai help me debug CodeRabbit configuration file.

Note: Be mindful of the bot's finite context window. It's strongly recommended to break down tasks such as reading entire modules into smaller chunks. For a focused discussion, use review comments to chat about specific files and their changes, instead of using the PR comments.

CodeRabbit Commands (Invoked using PR comments)

  • @coderabbitai pause to pause the reviews on a PR.
  • @coderabbitai resume to resume the paused reviews.
  • @coderabbitai review to trigger an incremental review. This is useful when automatic reviews are disabled for the repository.
  • @coderabbitai full review to do a full review from scratch and review all the files again.
  • @coderabbitai summary to regenerate the summary of the PR.
  • @coderabbitai generate docstrings to generate docstrings for this PR.
  • @coderabbitai resolve resolve all the CodeRabbit review comments.
  • @coderabbitai configuration to show the current CodeRabbit configuration for the repository.
  • @coderabbitai help to get help.

Other keywords and placeholders

  • Add @coderabbitai ignore anywhere in the PR description to prevent this PR from being reviewed.
  • Add @coderabbitai summary to generate the high-level summary at a specific location in the PR description.
  • Add @coderabbitai anywhere in the PR title to generate the title automatically.

CodeRabbit Configuration File (.coderabbit.yaml)

  • You can programmatically configure CodeRabbit by adding a .coderabbit.yaml file to the root of your repository.
  • Please see the configuration documentation for more information.
  • If your editor has YAML language server enabled, you can add the path at the top of this file to enable auto-completion and validation: # yaml-language-server: $schema=https://coderabbit.ai/integrations/schema.v2.json

Documentation and Community

  • Visit our Documentation for detailed information on how to use CodeRabbit.
  • Join our Discord Community to get help, request features, and share feedback.
  • Follow us on X/Twitter for updates and announcements.

@renovate renovate bot force-pushed the renovate/spring-security branch from 2dbcfe4 to f389c39 Compare March 17, 2025 23:42
@renovate renovate bot changed the title fix(deps): update spring security to v6.4.3 fix(deps): update spring security to v6.4.4 Mar 17, 2025
@renovate renovate bot force-pushed the renovate/spring-security branch from f389c39 to 059f39d Compare April 3, 2025 11:58
Copy link
Contributor Author

renovate bot commented Apr 3, 2025

Edited/Blocked Notification

Renovate will not automatically rebase this PR, because it does not recognize the last commit author and assumes somebody else may have edited the PR.

You can manually request rebase by checking the rebase/retry box above.

⚠️ Warning: custom changes will be lost.

Copy link

codecov bot commented Apr 3, 2025

Codecov Report

All modified and coverable lines are covered by tests ✅

📢 Thoughts on this report? Let us know!

@brettchaldecott brettchaldecott merged commit e56687e into main Apr 3, 2025
3 checks passed
@renovate renovate bot deleted the renovate/spring-security branch April 3, 2025 12:56
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

Successfully merging this pull request may close these issues.

1 participant