Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

fix(deps): update dependency org.springframework.security:spring-security-config to v6 #30

Open
wants to merge 1 commit into
base: master
Choose a base branch
from

Conversation

renovate[bot]
Copy link
Contributor

@renovate renovate bot commented Mar 6, 2020

This PR contains the following updates:

Package Change Age Adoption Passing Confidence
org.springframework.security:spring-security-config (source) 4.2.20.RELEASE -> 6.4.3 age adoption passing confidence

Warning

Some dependencies could not be looked up. Check the Dependency Dashboard for more information.


Release Notes

spring-projects/spring-security (org.springframework.security:spring-security-config)

v6.4.3

Compare Source

⭐ New Features

  • Add Support disableDefaultRegistrationPage to WebAuthnDsl #​16395

🪲 Bug Fixes

  • withValue used incorrectly #​16527
  • Fix for JdbcOneTimeTokenService cleanupExpiredTokens failing with PostgreSQL #​16344
  • Fix GenerateOneTimeTokenWebFilter double publish of chain.filter(...) #​16459
  • Fix Kotlin DSL webAuthn { } #​16338
  • Fix loader has changed while resolving nodes in WebAuthnWebDriverTests #​16463
  • Fix logoutRequestRepository not set on Saml2RelyingPartyInitiatedLogoutSuccessHandler #​16310
  • Implement Serializable for WebAuthnAuthentication #​16285
  • Make AuthorizationDecision Serializable #​16544
  • Make PublicKeyCredentialRequestOptions Serializable Backport #​16584
  • Make Saml2AuthenticationToken Serializable #​16287
  • Make WebAuthnAuthentication Serializable #​16273
  • Make WebAuthnAuthenticationRequestToken Serializable #​16602
  • Make WebAuthnAuthenticationTokenRequest Serializable #​16481
  • Misconfigured OAuth2LoginAuthenticationFilter when combining OAuth2 login and OAuth2 client configuration #​16466
  • OTT Should Use non-static member to capture the last OneTimeToken #​16471
  • webauthn js should ensure allowCredentials[].id is an ArrayBuffer #​16440

🔨 Dependency Upgrades

  • Bump ch.qos.logback:logback-classic from 1.5.15 to 1.5.16 #​16364
  • Bump com.nimbusds:oauth2-oidc-sdk from 9.43.5 to 9.43.6 #​16598
  • Bump com.webauthn4j:webauthn4j-core from 0.28.4.RELEASE to 0.28.5.RELEASE #​16523
  • Bump io.micrometer:micrometer-observation from 1.14.3 to 1.14.4 #​16565
  • Bump io.mockk:mockk from 1.13.14 to 1.13.16 #​16399
  • Bump io.projectreactor:reactor-bom from 2023.0.14 to 2023.0.15 #​16576
  • Bump io.rsocket:rsocket-bom from 1.1.4 to 1.1.5 #​16534
  • Bump org.hibernate.orm:hibernate-core from 6.6.7.Final to 6.6.8.Final #​16610
  • Bump org.junit:junit-bom from 5.11.3 to 5.11.4 #​16292
  • Bump org.springframework.data:spring-data-bom from 2024.1.2 to 2024.1.3 #​16611
  • Bump org.springframework.ldap:spring-ldap-core from 3.2.10 to 3.2.11 #​16597
  • Bump org.springframework:spring-framework-bom from 6.2.2 to 6.2.3 #​16599
  • Update to oauth2-oidc-sdk 9.43.5 #​16583

🔩 Build Updates

❤️ Contributors

Thank you to all the contributors who worked on this release:

@​Kehrlann, @​NeoTraveler, @​dependabot[bot], @​franticticktick, @​making, and @​ngocnhan-tran1996

v6.4.2

Compare Source

⭐ New Features

  • Add 6.4 Sample Serializations for Serializable classes #​16274
  • Add @inheritDoc to sessionIdChanged method #​16216
  • Fix typo in oauth2 resource server documentation #​16053
  • Fixed confusing phrasing in the docs for a better clarity. #​16169
  • Improve AuthorizationManager configuration error messages #​16194
  • Polish #​16148
  • Use Documentation Tags for Maven and Gradle in Getting Started #​16234
  • Add WebDriver WebAuthn test #​15969

🪲 Bug Fixes

  • Add Deprecated ObjectPostProcessor constructor #​16212
  • Add RuntimeHints for webauthn Javascript resource #​16159
  • Always return current ClientRegistration in loadAuthorizedClient #​16139
  • Avoid requesting an unnecessary attestation statement when creating a webauthn credential #​16252
  • CI is not using the correct secret for Develocity #​16263
  • Dark mode rendering issue with images on CSRF and Method Security pages #​16176
  • DefaultSaml2AuthenticatedPrincipal should define a serialVersionUID #​16163
  • Delay initialization of AuthenticationProvider in Global Authentication #​16147
  • Fix Documentation Typos #​16054
  • Correct OAuth2ClientHttpRequestInterceptor Usage Documentation #​16172
  • Fix Typo in 'What's New' Documentation #​16183
  • Fix WebAuthnWebdriverTests #​16279
  • Correct OpenSAML 5.x Documentation #​16195
  • Issue when using @AuthenticationPrincipal on interfaces #​16177
  • Mutate breaks functionality of StrictFirewallHttpHeaders with recently modified HttpHeaders#writabeHttpHeaders #​16261
  • Remove duplicate cache in AuthenticationPrincipalArgumentResolverand CurrentSecurityContextArgumentResolver #​16202
  • Resolve ObjectPostProcessor collisions between RSocket and WebFlux security configuration #​16161
  • Restore @AuthenticationPrincipal/@CurrentSecurityContext Interface Support #​16245
  • Restore Servlet 5 Compatiblity for CookieCsrfTokenRepository #​16220
  • Spelling error in opensaml.adoc #​16146
  • Update document regarding PublicKeyCredentialCreationOptions.attestation value #​16264
  • Verification Options Should Return Saved Transports for Credentials #​16084

🔨 Dependency Upgrades

  • Bump com.fasterxml.jackson:jackson-bom from 2.18.1 to 2.18.2 #​16184
  • Bump com.webauthn4j:webauthn4j-core from 0.28.2.RELEASE to 0.28.3.RELEASE #​16203
  • Bump io.micrometer:micrometer-observation from 1.14.1 to 1.14.2 #​16255
  • Bump io.projectreactor:reactor-bom from 2023.0.12 to 2023.0.13 #​16256
  • Bump org.gradle.wrapper-upgrade from 0.11.4 to 0.12 #​16209
  • Bump org.gretty:gretty from 4.1.5 to 4.1.6 #​16247
  • Bump org.hibernate.orm:hibernate-core from 6.6.2.Final to 6.6.3.Final #​16145
  • Bump org.htmlunit:htmlunit from 4.6.0 to 4.7.0 #​16205
  • Bump org.jfrog.buildinfo:build-info-extractor-gradle from 4.33.22 to 4.33.23 #​16180
  • Bump org.seleniumhq.selenium:htmlunit3-driver from 4.26.0 to 4.27.0 #​16204
  • Bump org.seleniumhq.selenium:selenium-java from 4.26.0 to 4.27.0 #​16167
  • Bump org.springframework.data:spring-data-bom from 2024.1.0 to 2024.1.1 #​16290
  • Bump org.springframework.ldap:spring-ldap-core from 3.2.8 to 3.2.10 #​16270
  • Bump org.springframework:spring-framework-bom from 6.2.0 to 6.2.1 #​16271

🔩 Build Updates

  • Bump @antora/collector-extension from 1.0.0 to 1.0.1 in /docs #​16239
  • Bump antora from 3.2.0-alpha.6 to 3.2.0-alpha.8 in /docs #​16237
  • Bump gradle/gradle-build-action from 2 to 3 #​16278
  • Remove 5.8.x and 6.2.x dependabot configuration #​16268
  • Remove 5.8.x from Auto Merge Forward Dependabot PRs #​15770

❤️ Contributors

Thank you to all the contributors who worked on this release:

@​12OneTwo12, @​Kehrlann, @​MuhammadNFadhil, @​OrangeDog, @​Spikhalskiy, @​dependabot[bot], @​harpreets789, @​kse-music, @​martin-tarjanyi, @​ngocnhan-tran1996, and @​ynojima

v6.4.1

Compare Source

🪲 Bug Fixes
  • Documentation images should render clearly in both light and dark mode #​16132
  • Fix conflicting bean names between @EnableWebSecurity and @EnableWebSocketSecurity #​16113
🔩 Build Updates
  • Update Antora UI Spring to v0.4.18 #​16112
❤️ Contributors

Thank you to all the contributors who worked on this release:

@​github-actions[bot] and @​ngocnhan-tran1996

v6.4.0

Compare Source

⭐ New Features
  • Add @FunctionalInterface to AuthorizationEventPublisher #​15934
  • Add DefaultResourcesFilter.webauthn() #​15970
  • Add deprecation notice for missing leading slashes #​16020
  • Code Cleanup #​15996
  • Document passkeys dependencies #​16107
  • Factor out some common object mocking in tests #​15396
  • Fix saml2 authentication guide docs #​16017
  • Improve documentation about CredentialsContainer #​15554
  • Improve Documentation on Adding a Custom Security Filter #​15893
  • Improve Error Message for Conflicting Filter Chains #​15992
  • Make it easier to determine where a filter chain has been defined #​15874
  • OIDC logout not working for JPA/JDBC OAuth2AuthorizationService because DefaultSaml2AuthenticatedPrincipal does not implement equality #​15346
  • Polish JdbcOneTimeTokenService #​15997
  • relying-party-registration doesn't allow placeholders in xml #​14645
  • Remove unnecessary parentheses and add static final field MockPortResolver#getServerPort #​15875
  • Support ServerExchangeRejectedHandler @Bean #​16063
🪲 Bug Fixes
  • An empty-string bearer token should result in an appropriate HTTP status code #​16037
  • AuthorizeReturnObject AOT support should register proxied class as well #​16106
  • Correct class name reference in WebFilterChainProxy JavaDoc #​16004
  • Fix typo javadoc some classes #​16022
  • Initialize OpenSAML in OpenSamlAssertingPartyMetadataRepository #​16055
  • IpAddressMatcher null pointer exception #​16104
  • OpenSamlAssertingPartyMetadataRepository should initialize OpenSAML #​16042
  • Support ServerWebExchangeFirewall @Bean #​15999
  • UniqueSecurityAnnotationScanner throws ConcurrentModificationException #​15906
🔨 Dependency Upgrades
  • Bump ch.qos.logback:logback-classic from 1.5.11 to 1.5.12 #​16005
  • Bump com.fasterxml.jackson:jackson-bom from 2.18.0 to 2.18.1 #​16007
  • Bump com.webauthn4j:webauthn4j-core from 0.28.1.RELEASE to 0.28.2.RELEASE #​16122
  • Bump io.freefair.gradle:aspectj-plugin from 8.10.2 to 8.11 #​16123
  • Bump io.micrometer:micrometer-observation from 1.14.0 to 1.14.1 #​16121
  • Bump io.projectreactor:reactor-bom from 2023.0.11 to 2023.0.12 #​16079
  • Bump org-bouncycastle from 1.78.1 to 1.79 #​16010
  • Bump org.hibernate.orm:hibernate-core from 6.6.1.Final to 6.6.2.Final #​16048
  • Bump org.hsqldb:hsqldb from 2.7.3 to 2.7.4 #​16028
  • Bump org.htmlunit:htmlunit from 4.5.0 to 4.6.0 #​16044
  • Bump org.junit:junit-bom from 5.11.2 to 5.11.3 #​15968
  • Bump org.seleniumhq.selenium:htmlunit3-driver from 4.25.0 to 4.26.0 #​16043
  • Bump org.seleniumhq.selenium:selenium-java from 4.25.0 to 4.26.0 #​16018
  • Bump org.springframework.data:spring-data-bom from 2024.0.5 to 2024.1.0 #​16124
  • Bump org.springframework.ldap:spring-ldap-core from 3.2.7 to 3.2.8 #​16097
  • Bump org.springframework:spring-framework-bom from 6.2.0-RC3 to 6.2.0 #​16096
🔩 Build Updates
  • Bump @antora/collector-extension from 1.0.0-beta.4 to 1.0.0-beta.5 in /docs #​16115
  • Update Antora UI Spring to v0.4.17 #​15929
❤️ Contributors

Thank you to all the contributors who worked on this release:

@​Chu3laMan, @​Kehrlann, @​Limm-jk, @​dcolazin, @​dependabot[bot], @​franticticktick, @​github-actions[bot], @​gzhao9, @​ig-jinwoo, @​jzheaux, @​kse-music, @​ngocnhan-tran1996, and @​nomoreFt

v6.3.7

Compare Source

⭐ New Features

  • Improve Stability of S101 CI Task #​16482

🪲 Bug Fixes

  • Fix logoutRequestRepository not set on Saml2RelyingPartyInitiatedLogoutSuccessHandler #​16093
  • Misconfigured OAuth2LoginAuthenticationFilter when combining OAuth2 login and OAuth2 client configuration #​16105

🔨 Dependency Upgrades

  • Bump ch.qos.logback:logback-classic from 1.5.15 to 1.5.16 #​16363
  • Bump com.nimbusds:oauth2-oidc-sdk from 9.43.5 to 9.43.6 #​16594
  • Bump io.mockk:mockk from 1.13.14 to 1.13.16 #​16400
  • Bump io.projectreactor:reactor-bom from 2023.0.14 to 2023.0.15 #​16577
  • Bump io.rsocket:rsocket-bom from 1.1.4 to 1.1.5 #​16533
  • Bump org.springframework.data:spring-data-bom from 2024.0.8 to 2024.0.9 #​16607
  • Bump org.springframework.ldap:spring-ldap-core from 3.2.10 to 3.2.11 #​16595
  • Bump org.springframework:spring-framework-bom from 6.1.16 to 6.1.17 #​16596
  • Update to oauth2-oidc-sdk 9.43.5 #​16582

🔩 Build Updates

  • Bump @springio/asciidoctor-extensions from 1.0.0-alpha.14 to 1.0.0-alpha.16 in /docs #​16519
  • Troubleshoot missing GChat notifications #​16423

❤️ Contributors

Thank you to all the contributors who worked on this release:

@​dependabot[bot] and @​sawprogramming

v6.3.6

Compare Source

🪲 Bug Fixes
  • Always return current ClientRegistration in loadAuthorizedClient #​16138
  • CI is not using the correct secret for Develocity #​16262
  • Dark mode rendering issue with images on CSRF and Method Security pages #​16175
  • Delay initialization AuthenticationProvider in Global Authentication #​16050
  • Do not eagerly construct UserDetailsService bean in Global Authentication #​16144
  • Documentation images should render clearly in both light and dark mode #​16131
  • Mutate breaks functionality of StrictFirewallHttpHeaders with recently modified HttpHeaders#writabeHttpHeaders #​16069
  • OidcBackChannelLogoutWebFilter error response is not a correct JSON #​16229
  • Restore Servlet 5 Compatiblity for CookieCsrfTokenRepository #​16219
🔨 Dependency Upgrades
  • Bump io.projectreactor:reactor-bom from 2023.0.12 to 2023.0.13 #​16257
  • Bump org.gretty:gretty from 4.1.5 to 4.1.6 #​16246
  • Bump org.jfrog.buildinfo:build-info-extractor-gradle from 4.33.22 to 4.33.23 #​16179
  • Bump org.springframework.data:spring-data-bom from 2024.0.6 to 2024.0.7 #​16289
  • Bump org.springframework.ldap:spring-ldap-core from 3.2.8 to 3.2.10 #​16269
  • Bump org.springframework:spring-framework-bom from 6.1.15 to 6.1.16 #​16272
🔩 Build Updates
  • Bump antora from 3.2.0-alpha.6 to 3.2.0-alpha.8 in /docs #​16244
  • Update Antora UI Spring to v0.4.18 #​16110
❤️ Contributors

Thank you to all the contributors who worked on this release:

@​dependabot[bot], @​github-actions[bot], and @​kse-music

v6.3.5

Compare Source

⭐ New Features
  • Support ServerExchangeRejectedHandler @Bean #​16062
  • Supporting logout+jwt for back-channel logout with spring-webflux #​15702
🪲 Bug Fixes
  • Align DelegatingAuthenticationConverter Constructors #​15949
  • An empty-string bearer token should result in an appropriate HTTP status code #​16036
  • IpAddressMatcher null pointer exception #​15527
  • RequestMatcherDelegatingAuthorizationManager should be post-processable #​15981
  • Support ServerWebExchangeFirewall @Bean #​15991
  • Unhandled exception in CookieRequestCache results in 500 Internal Server Error #​15986
  • Update logout.adoc: Fix Customizing Logout Success Example #​15956
🔨 Dependency Upgrades
  • Bump ch.qos.logback:logback-classic from 1.5.11 to 1.5.12 #​16006
  • Bump com.fasterxml.jackson:jackson-bom from 2.17.2 to 2.17.3 #​16032
  • Bump io.micrometer:micrometer-observation from 1.12.12 to 1.12.13 #​16126
  • Bump io.projectreactor:reactor-bom from 2023.0.11 to 2023.0.12 #​16082
  • Bump org.hsqldb:hsqldb from 2.7.3 to 2.7.4 #​16033
  • Bump org.springframework.data:spring-data-bom from 2024.0.5 to 2024.0.6 #​16125
  • Bump org.springframework.ldap:spring-ldap-core from 3.2.7 to 3.2.8 #​16102
  • Bump org.springframework:spring-framework-bom from 6.1.14 to 6.1.15 #​16101
🔩 Build Updates
  • Bump @antora/collector-extension from 1.0.0-beta.4 to 1.0.0-beta.5 in /docs #​16117
  • Update Antora UI Spring to v0.4.17 #​15930
❤️ Contributors

Thank you to all the contributors who worked on this release:

@​asimuleo, @​dependabot[bot], @​github-actions[bot], and @​kse-music

v6.3.4

Compare Source

🪲 Bug Fixes
  • Annotation expression template processing should not fail on Class parameter types #​15711
  • Disabling credentials erasure on custom AuthenticationManager is not working #​15808
  • Documentation inconsistency in AuthorizationManager's verify method return type #​15822
  • Methods annotated with @PostFilter are processed twice by PostFilterAuthorizationMethodInterceptor #​15676
  • OidcBackChannelLogoutTokenValidator should not construct when missing OIDC Provider Issuer #​15868
  • SecurityJackson2Modules.getModules(): Cannot load module org.springframework.security.cas.jackson2.CasJackson2Module #​15767
  • The additionalParameters array parameter of OAuth2AuthorizationRequest causes the authorizationRequestUri to be incorrect #​15829
🔨 Dependency Upgrades
  • Bump ch.qos.logback:logback-classic from 1.5.10 to 1.5.11 #​15926
  • Bump io.micrometer:micrometer-observation from 1.12.10 to 1.12.11 #​15917
  • Bump io.mockk:mockk from 1.13.12 to 1.13.13 #​15897
  • Bump io.projectreactor:reactor-bom from 2023.0.10 to 2023.0.11 #​15925
  • Bump jakarta.servlet.jsp.jstl:jakarta.servlet.jsp.jstl-api from 3.0.1 to 3.0.2 #​15694
  • Bump org-eclipse-jetty from 11.0.23 to 11.0.24 #​15731
  • Bump org.jfrog.buildinfo:build-info-extractor-gradle from 4.33.21 to 4.33.22 #​15761
  • Bump org.junit:junit-bom from 5.10.4 to 5.10.5 #​15883
  • Bump org.springframework.data:spring-data-bom from 2024.0.4 to 2024.0.5 #​15958
  • Bump org.springframework.ldap:spring-ldap-core from 3.2.6 to 3.2.7 #​15944
  • Bump org.springframework:spring-framework-bom from 6.1.13 to 6.1.14 #​15945
🔩 Build Updates
  • Bump @antora/collector-extension from 1.0.0-beta.2 to 1.0.0-beta.3 in /docs #​15907
  • Bump @springio/asciidoctor-extensions from 1.0.0-alpha.13 to 1.0.0-alpha.14 in /docs #​15836
  • Migrate slack notifications to GChat #​15668
  • Release 6.3.4 #​15964
  • Update eclipse/vscode configuration to use -parameters #​15681
❤️ Contributors

Thank you to all the contributors who worked on this release:

@​dependabot[bot] and @​kse-music

v6.3.3

Compare Source

🪲 Bug Fixes
  • ObservationRegistry is never post-processed #​15658
🔨 Dependency Upgrades
  • Bump org-eclipse-jetty from 11.0.22 to 11.0.23 #​15664
❤️ Contributors

Thank you to all the contributors who worked on this release:

@​dependabot[bot]

v6.3.2

Compare Source

⭐ New Features

  • ActiveDirectoryLdapAuthenticationProvider does not implement support for multiple urls #​15495
  • Document the role of CredentialsContainer #​15321
  • OIDC Backchannel Logout should allow logout tokens having typ header of logout+jwt #​15410

🪲 Bug Fixes

  • A broken link in Spring Security reference #​15297
  • Documentation for ServletBearerExchangeFilterFunction incomplete or incorrect #​15460
  • EnableMethodSecurity should publish only one bean of each AuthorizationAdvisor #​15592
  • Fix Compromised Password Checker Docs Sample Not Working #​15305
  • Fix for #​15172 introduces significant performance degredation #​15324
  • Pre/PostAuthorize should not ignore HandleAuthorizationDenied#handlerClass when ApplicationContext is not provided #​15535
  • Update prerequisites documentation with Java 17 #​15340
  • Use Correct Meta-Annotation in Kotlin Sample #​15472
  • Using sec:authorize in JSPX causes 'java.lang.NullPointerException: Cannot invoke "jakarta.servlet.ServletRegistration.getClassName()" because "registration" is null' #​15440

🔨 Dependency Upgrades

  • Bump ch.qos.logback:logback-classic from 1.5.6 to 1.5.7 #​15619
  • Bump com.fasterxml.jackson:jackson-bom from 2.17.1 to 2.17.2 #​15374
  • Bump com.github.spullara.mustache.java:compiler from 0.9.13 to 0.9.14 #​15373
  • Bump io.micrometer:micrometer-observation from 1.12.7 to 1.12.8 #​15383
  • Bump io.micrometer:micrometer-observation from 1.12.8 to 1.12.9 #​15581
  • Bump io.mockk:mockk from 1.13.11 to 1.13.12 #​15430
  • Bump io.projectreactor:reactor-bom from 2023.0.7 to 2023.0.8 #​15388
  • Bump io.projectreactor:reactor-bom from 2023.0.8 to 2023.0.9 #​15597
  • Bump jakarta.servlet.jsp.jstl:jakarta.servlet.jsp.jstl-api from 3.0.0 to 3.0.1 #​15582
  • Bump org-apache-maven-resolver from 1.9.20 to 1.9.21 #​15372
  • Bump org-apache-maven-resolver from 1.9.21 to 1.9.22 #​15545
  • Bump org-eclipse-jetty from 11.0.21 to 11.0.22 #​15356
  • Bump org.apache.maven:maven-resolver-provider from 3.9.7 to 3.9.8 #​15268
  • Bump org.apache.maven:maven-resolver-provider from 3.9.8 to 3.9.9 #​15642
  • Bump org.gretty:gretty from 4.1.4 to 4.1.5 #​15431
  • Bump org.hibernate.orm:hibernate-core from 6.4.9.Final to 6.4.10.Final #​15530
  • Bump org.jetbrains.kotlin:kotlin-bom from 1.9.24 to 1.9.25 #​15456
  • Bump org.jetbrains.kotlin:kotlin-gradle-plugin from 1.9.24 to 1.9.25 #​15455
  • Bump org.jfrog.buildinfo:build-info-extractor-gradle from 4.33.19 to 4.33.20 #​15267
  • Bump org.junit:junit-bom from 5.10.2 to 5.10.3 #​15315
  • Bump org.skyscreamer:jsonassert from 1.5.1 to 1.5.3 #​15336
  • Bump org.slf4j:slf4j-api from 2.0.13 to 2.0.14 #​15529
  • Bump org.slf4j:slf4j-api from 2.0.14 to 2.0.15 #​15546
  • Bump org.slf4j:slf4j-api from 2.0.15 to 2.0.16 #​15571
  • Bump org.springframework.data:spring-data-bom from 2024.0.1 to 2024.0.2 #​15421
  • Bump org.springframework.data:spring-data-bom from 2024.0.2 to 2024.0.3 #​15643
  • Bump org.springframework.ldap:spring-ldap-core from 3.2.4 to 3.2.6 #​15620
  • Bump org.springframework:spring-framework-bom from 6.1.10 to 6.1.11 #​15402
  • Bump org.springframework:spring-framework-bom from 6.1.11 to 6.1.12 #​15613
  • Bump org.springframework:spring-framework-bom from 6.1.9 to 6.1.10 #​15279

🔩 Build Updates

  • Automate check of expected branch version #​15310
  • Bump @antora/collector-extension from 1.0.0-alpha.4 to 1.0.0-alpha.6 in /docs #​15449
  • Bump @antora/collector-extension from 1.0.0-alpha.6 to 1.0.0-alpha.7 in /docs #​15482
  • Bump @antora/collector-extension from 1.0.0-alpha.7 to 1.0.0-beta.1 in /docs #​15560
  • Bump @antora/collector-extension from 1.0.0-beta.1 to 1.0.0-beta.2 in /docs #​15637
  • Bump @springio/antora-extensions from 1.11.1 to 1.12.0 in /docs #​15418
  • Bump @springio/antora-extensions from 1.12.0 to 1.13.0 in /docs #​15517
  • Bump @springio/antora-extensions from 1.13.0 to 1.13.1 in /docs #​15561
  • Bump @springio/antora-extensions from 1.13.1 to 1.14.2 in /docs #​15636
  • Bump @springio/asciidoctor-extensions from 1.0.0-alpha.10 to 1.0.0-alpha.11 in /docs #​15419
  • Bump @springio/asciidoctor-extensions from 1.0.0-alpha.11 to 1.0.0-alpha.12 in /docs #​15515
  • Bump antora from 3.2.0-alpha.4 to 3.2.0-alpha.5 in /docs #​15329
  • Bump antora from 3.2.0-alpha.5 to 3.2.0-alpha.6 in /docs #​15480
  • Bump com.gradle.develocity from 3.17.5 to 3.17.6 #​15464
  • Bump io-spring-javaformat from 0.0.42 to 0.0.43 #​15650
  • Fix typos and formatting in documentation #​15380
  • Migrate slack notifications to GChat #​15505
  • Use explicit types instead of var #​15537

❤️ Contributors

Thank you to all the contributors who worked on this release:

@​Kehrlann, @​dependabot[bot], and @​tahakorkem

v6.3.1

Compare Source

⭐ New Features

  • Clarify the behavior of Concurrent Session Management when an IdP is involved #​15071
  • Mention all required dependencies in LDAP documentation #​15245
  • Minor docs fix #​15144

🪲 Bug Fixes

  • AbstractRequestMatcherRegistry#requestMatchers should pick MvcRequestMatcher when using MockMvc #​15211
  • Assert WebSession is not null #​15179
  • DispatcherServletDelegatingRequestMatcher causes errors when running tests with MockMvc #​15197
  • Documentation clarification after #​12783 has been closed is needed. #​15208
  • Fix Java example in multitenanci.adoc #​15151
  • Fix Kotlin example in authorize-http-requests.adoc #​15129
  • Incorrect documentation for OIDC Back-Channel Logout #​15212
  • IpAddressMatcher.matches(String address) still accepts URLs #​15172
  • LDIF file on official documentation breaks the startup process #​15167
  • Link to article with remember-me-persistent-token strategy is broken #​15149
  • OpenSaml4AssertionValidator is not respecting clock skew settings #​15183
  • Resolving invalid CSRF token values is not consistent #​15186
  • spring-security/docs/modules/ROOT/pages/servlet/authorization /method-security #​15143
  • SpringOpaqueTokenIntrospector does not add scopes as granted authorities properly #​15165

🔨 Dependency Upgrades

  • Bump io.micrometer:micrometer-observation from 1.12.6 to 1.12.7 #​15225
  • Bump io.projectreactor:reactor-bom from 2023.0.6 to 2023.0.7 #​15229
  • Bump org.apache.directory.shared:shared-ldap from 0.9.15 to 0.9.19 #​15161
  • Bump org.apache.maven:maven-resolver-provider from 3.9.6 to 3.9.7 #​15168
  • Bump org.gretty:gretty from 4.1.3 to 4.1.4 #​15133
  • Bump org.hibernate.orm:hibernate-core from 6.4.8.Final to 6.4.9.Final #​15228
  • Bump org.hsqldb:hsqldb from 2.7.2 to 2.7.3 #​15193
  • Bump org.springframework.data:spring-data-bom from 2024.0.0 to 2024.0.1 #​15260
  • Bump org.springframework.ldap:spring-ldap-core from 3.2.3 to 3.2.4 #​15251
  • Bump org.springframework:spring-framework-bom from 6.1.7 to 6.1.8 #​15134
  • Bump org.springframework:spring-framework-bom from 6.1.8 to 6.1.9 #​15252

🔩 Build Updates

  • Bump @antora/collector-extension from 1.0.0-alpha.3 to 1.0.0-alpha.4 in /docs #​15159
  • Bump @springio/antora-extensions from 1.10.0 to 1.11.1 in /docs #​15141
  • Bump com.gradle.develocity from 3.17.4 to 3.17.5 #​15239
  • Bump gradle/gradle-build-action from 2 to 3 #​15157
  • Bump io-spring-javaformat from 0.0.41 to 0.0.42 #​15219
  • Bump org.jfrog.buildinfo:build-info-extractor-gradle from 4.33.15 to 4.33.16 #​15176
  • Bump org.jfrog.buildinfo:build-info-extractor-gradle from 4.33.16 to 4.33.17 #​15218
  • Bump org.jfrog.buildinfo:build-info-extractor-gradle from 4.33.17 to 4.33.19 #​15261
  • Bump spring-io/spring-doc-actions from 17ed79e to 5a57bcc #​15139

❤️ Contributors

Thank you to all the contributors who worked on this release:

@​dependabot[bot] and @​theHacker

v6.3.0

Compare Source

⭐ New Features

  • Add getters to OAuth2AuthorizedClientId #​13648
  • Add timeout defaults to JwtDecoders #​14890
  • doc: added hint to declare GrantedAuthorityDefaults as infrastructure bean #​15065
  • Improve logging for Global Authentication #​14711
  • Minor docs fix #​15043
  • Minor Documentation update on import needed for using Kotlin DSL #​14969
  • OAuth2 Client Authentication docs are incomplete #​14982
  • Proofread CasAuthenticationFilter documentation #​14883
  • Replace "Spring Boot 2.x" with "Spring Boot" #​14919
  • Simplify Disabling application/x-www-form-urlencoded Encoding Client ID and Secret #​14859
  • Support Specifying Identifier for relying-party-registrations Element #​14487
  • Update What's New in 6.3 #​14918

🪲 Bug Fixes

  • Do Not Invalidate Current Session When Its Registered #​15066
  • Fix MethodAuthorizationDeniedPostProcessor does not exist in java doc #​14955
  • fix docs error in AuthenticatedReactiveAuthorizationManager #​14979
  • OIDC Logout section is not shown in the navbar #​15113
  • Wrong information for RequestCacheAwareFilter in the Spring Security documentation. #​14996

🔨 Dependency Upgrades

  • Bump ch.qos.logback:logback-classic from 1.5.5 to 1.5.6 #​14926
  • Bump com.fasterxml.jackson:jackson-bom from 2.17.0 to 2.17.1 #​15010
  • Bump com.gradle.develocity from 3.17.2 to 3.17.3 #​15051
  • Bump com.gradle.develocity from 3.17.3 to 3.17.4 #​15104
  • Bump io.micrometer:micrometer-observation from 1.12.5 to 1.12.6 #​15068
  • Bump io.mockk:mockk from 1.13.10 to 1.13.11 #​15086
  • Bump io.projectreactor:reactor-bom from 2023.0.5 to 2023.0.6 [#​15076](https

Configuration

📅 Schedule: Branch creation - At any time (no schedule defined), Automerge - At any time (no schedule defined).

🚦 Automerge: Disabled by config. Please merge this manually once you are satisfied.

Rebasing: Whenever PR becomes conflicted, or you tick the rebase/retry checkbox.

🔕 Ignore: Close this PR and you won't be reminded about this update again.


  • If you want to rebase/retry this PR, check this box

This PR was generated by Mend Renovate. View the repository job log.

@renovate renovate bot force-pushed the renovate/major-spring-security branch 4 times, most recently from 402b955 to 3427630 Compare March 10, 2020 12:27
@renovate renovate bot changed the title chore(deps): update dependency org.springframework.security:spring-security-web to v5 chore(deps): update spring security to v5 (major) Mar 10, 2020
@renovate renovate bot force-pushed the renovate/major-spring-security branch from 3427630 to 45be80a Compare March 10, 2020 13:35
@renovate renovate bot changed the title chore(deps): update spring security to v5 (major) Update spring security to v5 (major) Mar 10, 2020
@renovate renovate bot changed the title Update spring security to v5 (major) Update dependency org.springframework.security:spring-security-web to v5 Mar 12, 2020
@renovate renovate bot changed the title Update dependency org.springframework.security:spring-security-web to v5 Update spring security to v5 (major) Mar 13, 2020
@renovate renovate bot force-pushed the renovate/major-spring-security branch 2 times, most recently from 7d5fa9b to bb23666 Compare March 16, 2020 17:42
@renovate renovate bot force-pushed the renovate/major-spring-security branch from bb23666 to f0ad4dc Compare March 31, 2020 23:58
@renovate renovate bot force-pushed the renovate/major-spring-security branch from f0ad4dc to 4817c20 Compare April 28, 2020 17:50
@renovate renovate bot force-pushed the renovate/major-spring-security branch 4 times, most recently from 20e894a to e33b567 Compare May 12, 2020 17:35
@renovate renovate bot force-pushed the renovate/major-spring-security branch from e33b567 to 2d2a8a4 Compare May 15, 2020 19:27
@renovate renovate bot force-pushed the renovate/major-spring-security branch 4 times, most recently from cd50dd6 to 1df1ee2 Compare June 9, 2020 10:21
@renovate renovate bot force-pushed the renovate/major-spring-security branch 4 times, most recently from 05ca0ce to 1cbad5f Compare July 21, 2020 08:32
@renovate renovate bot force-pushed the renovate/major-spring-security branch 3 times, most recently from 3540d22 to 4d45fc4 Compare August 5, 2020 17:20
@renovate renovate bot force-pushed the renovate/major-spring-security branch from 4d45fc4 to 35a9526 Compare August 16, 2020 05:27
@renovate renovate bot force-pushed the renovate/major-spring-security branch 2 times, most recently from 5458f41 to 4deec6a Compare September 28, 2022 17:53
@renovate renovate bot force-pushed the renovate/major-spring-security branch from 4deec6a to ec6fa4c Compare October 17, 2022 21:20
@renovate renovate bot force-pushed the renovate/major-spring-security branch from ec6fa4c to 23e33d1 Compare October 31, 2022 17:44
@renovate renovate bot force-pushed the renovate/major-spring-security branch from 23e33d1 to 8e7aaa6 Compare November 21, 2022 16:53
@renovate renovate bot changed the title Update spring security to v5 (major) Update spring security to v6 (major) Nov 21, 2022
@renovate renovate bot force-pushed the renovate/major-spring-security branch from 8e7aaa6 to 072a28e Compare March 16, 2023 14:12
@renovate renovate bot changed the title Update spring security to v6 (major) fix(deps): update dependency org.springframework.security:spring-security-config to v6 Mar 16, 2023
@renovate renovate bot force-pushed the renovate/major-spring-security branch from 072a28e to 39b4cde Compare April 17, 2023 18:15
@renovate renovate bot force-pushed the renovate/major-spring-security branch from 39b4cde to 59ce0f6 Compare May 28, 2023 08:44
@renovate renovate bot force-pushed the renovate/major-spring-security branch from 59ce0f6 to 3bb0737 Compare June 19, 2023 19:49
@renovate renovate bot force-pushed the renovate/major-spring-security branch from 3bb0737 to 096a1ef Compare July 18, 2023 00:41
@renovate renovate bot force-pushed the renovate/major-spring-security branch from 096a1ef to 80f44d2 Compare August 21, 2023 20:45
@renovate renovate bot force-pushed the renovate/major-spring-security branch from 80f44d2 to ffe4fbf Compare September 18, 2023 18:15
@renovate renovate bot force-pushed the renovate/major-spring-security branch from ffe4fbf to 300c984 Compare October 16, 2023 19:44
@renovate renovate bot force-pushed the renovate/major-spring-security branch from 300c984 to cfdd34c Compare November 20, 2023 17:21
@renovate renovate bot force-pushed the renovate/major-spring-security branch from cfdd34c to e89229c Compare December 18, 2023 19:09
@renovate renovate bot force-pushed the renovate/major-spring-security branch from e89229c to 69d794a Compare February 16, 2024 21:12
@renovate renovate bot force-pushed the renovate/major-spring-security branch from 69d794a to 6eaed77 Compare March 18, 2024 13:11
@renovate renovate bot force-pushed the renovate/major-spring-security branch from 6eaed77 to 78affb2 Compare April 15, 2024 18:13
@renovate renovate bot force-pushed the renovate/major-spring-security branch from 78affb2 to 2ec0db9 Compare May 20, 2024 18:25
@renovate renovate bot force-pushed the renovate/major-spring-security branch from 2ec0db9 to 8d9a2d2 Compare June 17, 2024 21:04
@renovate renovate bot force-pushed the renovate/major-spring-security branch 2 times, most recently from de1ca30 to c124123 Compare August 21, 2024 17:23
@renovate renovate bot force-pushed the renovate/major-spring-security branch from c124123 to 7093666 Compare October 21, 2024 20:24
@renovate renovate bot force-pushed the renovate/major-spring-security branch 2 times, most recently from ed6ba31 to 8bbf624 Compare November 21, 2024 05:17
@renovate renovate bot force-pushed the renovate/major-spring-security branch from 8bbf624 to afcbc0a Compare December 16, 2024 16:57
@renovate renovate bot force-pushed the renovate/major-spring-security branch from afcbc0a to c11fa70 Compare February 18, 2025 19:10
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

Successfully merging this pull request may close these issues.

0 participants