Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Update dependency org.springframework.security:spring-security-config to v6 #46

Open
wants to merge 1 commit into
base: master
Choose a base branch
from

Conversation

renovate[bot]
Copy link
Contributor

@renovate renovate bot commented Nov 21, 2022

This PR contains the following updates:

Package Change Age Adoption Passing Confidence
org.springframework.security:spring-security-config (source) 5.6.12 -> 6.4.2 age adoption passing confidence

Release Notes

spring-projects/spring-security (org.springframework.security:spring-security-config)

v6.4.2

Compare Source

⭐ New Features

  • Add 6.4 Sample Serializations for Serializable classes #​16274
  • Add @inheritDoc to sessionIdChanged method #​16216
  • Fix typo in oauth2 resource server documentation #​16053
  • Fixed confusing phrasing in the docs for a better clarity. #​16169
  • Improve AuthorizationManager configuration error messages #​16194
  • Polish #​16148
  • Use Documentation Tags for Maven and Gradle in Getting Started #​16234
  • webauthn: add webdriver test #​15969

🪲 Bug Fixes

  • Add Deprecated ObjectPostProcessor constructor #​16212
  • Add RuntimeHints for webauthn Javascript resource #​16159
  • Always return current ClientRegistration in loadAuthorizedClient #​16139
  • Avoid requesting an unnecessary attestation statement when creating a webauthn credential #​16252
  • Breaking Change after upgrading to 6.4.1 via Spring Boot 3.4.0 #​16174
  • CI is not using the correct secret for Develocity #​16263
  • Dark mode rendering issue with images on CSRF and Method Security pages #​16176
  • DefaultSaml2AuthenticatedPrincipal does not define serialVersionUID #​16163
  • Delay initialization AuthenticationProvider in Global Authentication #​16147
  • Fix Documentation Typos #​16054
  • Fix OAuth2 documentation: Correct OAuth2ClientHttpRequestInterceptor usage #​16172
  • Fix Typo in 'What's New' Documentation #​16183
  • Fix WebAuthnWebdriverTests #​16279
  • Fix: Correct OpenSAML 5.x Documentation #​16195
  • Issue when using @AuthenticationPrincipal on interfaces #​16177
  • Mutate breaks functionality of StrictFirewallHttpHeaders with recently modified HttpHeaders#writabeHttpHeaders #​16261
  • Remove duplicate cache in AuthenticationPrincipalArgumentResolver、and CurrentSecurityContextArgumentResolver #​16202
  • Resolve ObjectPostProcessor collisions between RSocket and WebFlux security configuration #​16161
  • Restore @AuthenticationPrincipal/@CurrentSecurityContext Interface Support #​16245
  • Restore Servlet 5 Compatiblity for CookieCsrfTokenRepository #​16220
  • Spelling error in opensaml.adoc #​16146
  • Update document regarding PublicKeyCredentialCreationOptions.attestation value #​16264
  • Verification Options do not Return Saved Transports for Credentials #​16084

🔨 Dependency Upgrades

  • Bump com.fasterxml.jackson:jackson-bom from 2.18.1 to 2.18.2 #​16184
  • Bump com.webauthn4j:webauthn4j-core from 0.28.2.RELEASE to 0.28.3.RELEASE #​16203
  • Bump io.micrometer:micrometer-observation from 1.14.1 to 1.14.2 #​16255
  • Bump io.projectreactor:reactor-bom from 2023.0.12 to 2023.0.13 #​16256
  • Bump org.gradle.wrapper-upgrade from 0.11.4 to 0.12 #​16209
  • Bump org.gretty:gretty from 4.1.5 to 4.1.6 #​16247
  • Bump org.hibernate.orm:hibernate-core from 6.6.2.Final to 6.6.3.Final #​16145
  • Bump org.htmlunit:htmlunit from 4.6.0 to 4.7.0 #​16205
  • Bump org.jfrog.buildinfo:build-info-extractor-gradle from 4.33.22 to 4.33.23 #​16180
  • Bump org.seleniumhq.selenium:htmlunit3-driver from 4.26.0 to 4.27.0 #​16204
  • Bump org.seleniumhq.selenium:selenium-java from 4.26.0 to 4.27.0 #​16167
  • Bump org.springframework.data:spring-data-bom from 2024.1.0 to 2024.1.1 #​16290
  • Bump org.springframework.ldap:spring-ldap-core from 3.2.8 to 3.2.10 #​16270
  • Bump org.springframework:spring-framework-bom from 6.2.0 to 6.2.1 #​16271

🔩 Build Updates

  • Bump @antora/collector-extension from 1.0.0 to 1.0.1 in /docs #​16239
  • Bump antora from 3.2.0-alpha.6 to 3.2.0-alpha.8 in /docs #​16237
  • Bump gradle/gradle-build-action from 2 to 3 #​16278
  • Remove 5.8.x and 6.2.x dependabot configuration #​16268
  • Remove 5.8.x from Auto Merge Forward Dependabot PRs #​15770

❤️ Contributors

Thank you to all the contributors who worked on this release:

@​12OneTwo12, @​Kehrlann, @​MuhammadNFadhil, @​OrangeDog, @​Spikhalskiy, @​dependabot[bot], @​harpreets789, @​kse-music, @​martin-tarjanyi, @​ngocnhan-tran1996, and @​ynojima

v6.4.1

Compare Source

🪲 Bug Fixes

  • Documentation images should render clearly in both light and dark mode #​16132
  • Fix conflicting bean names between @EnableWebSecurity and @EnableWebSocketSecurity #​16113

🔩 Build Updates

  • Update Antora UI Spring to v0.4.18 #​16112

❤️ Contributors

Thank you to all the contributors who worked on this release:

@​github-actions[bot] and @​ngocnhan-tran1996

v6.4.0

Compare Source

⭐ New Features

  • Add @FunctionalInterface to AuthorizationEventPublisher #​15934
  • Add DefaultResourcesFilter.webauthn() #​15970
  • Add deprecation notice for missing leading slashes #​16020
  • Code Cleanup #​15996
  • Document passkeys dependencies #​16107
  • Factor out some common object mocking in tests #​15396
  • Fix saml2 authentication guide docs #​16017
  • Improve documentation about CredentialsContainer #​15554
  • Improve Documentation on Adding a Custom Security Filter #​15893
  • Improve Error Message for Conflicting Filter Chains #​15992
  • Make it easier to determine where a filter chain has been defined #​15874
  • OIDC logout not working for JPA/JDBC OAuth2AuthorizationService because DefaultSaml2AuthenticatedPrincipal does not implement equality #​15346
  • Polish JdbcOneTimeTokenService #​15997
  • relying-party-registration doesn't allow placeholders in xml #​14645
  • Remove unnecessary parentheses and add static final field MockPortResolver#getServerPort #​15875
  • Support ServerExchangeRejectedHandler @Bean #​16063

🪲 Bug Fixes

  • An empty-string bearer token should result in an appropriate HTTP status code #​16037
  • AuthorizeReturnObject AOT support should register proxied class as well #​16106
  • Correct class name reference in WebFilterChainProxy JavaDoc #​16004
  • Fix typo javadoc some classes #​16022
  • Initialize OpenSAML in OpenSamlAssertingPartyMetadataRepository #​16055
  • IpAddressMatcher null pointer exception #​16104
  • OpenSamlAssertingPartyMetadataRepository should initialize OpenSAML #​16042
  • Support ServerWebExchangeFirewall @Bean #​15999
  • UniqueSecurityAnnotationScanner throws ConcurrentModificationException #​15906

🔨 Dependency Upgrades

  • Bump ch.qos.logback:logback-classic from 1.5.11 to 1.5.12 #​16005
  • Bump com.fasterxml.jackson:jackson-bom from 2.18.0 to 2.18.1 #​16007
  • Bump com.webauthn4j:webauthn4j-core from 0.28.1.RELEASE to 0.28.2.RELEASE #​16122
  • Bump io.freefair.gradle:aspectj-plugin from 8.10.2 to 8.11 #​16123
  • Bump io.micrometer:micrometer-observation from 1.14.0 to 1.14.1 #​16121
  • Bump io.projectreactor:reactor-bom from 2023.0.11 to 2023.0.12 #​16079
  • Bump org-bouncycastle from 1.78.1 to 1.79 #​16010
  • Bump org.hibernate.orm:hibernate-core from 6.6.1.Final to 6.6.2.Final #​16048
  • Bump org.hsqldb:hsqldb from 2.7.3 to 2.7.4 #​16028
  • Bump org.htmlunit:htmlunit from 4.5.0 to 4.6.0 #​16044
  • Bump org.junit:junit-bom from 5.11.2 to 5.11.3 #​15968
  • Bump org.seleniumhq.selenium:htmlunit3-driver from 4.25.0 to 4.26.0 #​16043
  • Bump org.seleniumhq.selenium:selenium-java from 4.25.0 to 4.26.0 #​16018
  • Bump org.springframework.data:spring-data-bom from 2024.0.5 to 2024.1.0 #​16124
  • Bump org.springframework.ldap:spring-ldap-core from 3.2.7 to 3.2.8 #​16097
  • Bump org.springframework:spring-framework-bom from 6.2.0-RC3 to 6.2.0 #​16096

🔩 Build Updates

  • Bump @antora/collector-extension from 1.0.0-beta.4 to 1.0.0-beta.5 in /docs #​16115
  • Update Antora UI Spring to v0.4.17 #​15929

❤️ Contributors

Thank you to all the contributors who worked on this release:

@​Chu3laMan, @​Kehrlann, @​Limm-jk, @​dcolazin, @​dependabot[bot], @​franticticktick, @​github-actions[bot], @​gzhao9, @​ig-jinwoo, @​jzheaux, @​kse-music, @​ngocnhan-tran1996, and @​nomoreFt

v6.3.6

Compare Source

🪲 Bug Fixes

  • Always return current ClientRegistration in loadAuthorizedClient #​16138
  • CI is not using the correct secret for Develocity #​16262
  • Dark mode rendering issue with images on CSRF and Method Security pages #​16175
  • Delay initialization AuthenticationProvider in Global Authentication #​16050
  • Do not eagerly construct UserDetailsService bean in Global Authentication #​16144
  • Documentation images should render clearly in both light and dark mode #​16131
  • Mutate breaks functionality of StrictFirewallHttpHeaders with recently modified HttpHeaders#writabeHttpHeaders #​16069
  • OidcBackChannelLogoutWebFilter error response is not a correct JSON #​16229
  • Restore Servlet 5 Compatiblity for CookieCsrfTokenRepository #​16219

🔨 Dependency Upgrades

  • Bump io.projectreactor:reactor-bom from 2023.0.12 to 2023.0.13 #​16257
  • Bump org.gretty:gretty from 4.1.5 to 4.1.6 #​16246
  • Bump org.jfrog.buildinfo:build-info-extractor-gradle from 4.33.22 to 4.33.23 #​16179
  • Bump org.springframework.data:spring-data-bom from 2024.0.6 to 2024.0.7 #​16289
  • Bump org.springframework.ldap:spring-ldap-core from 3.2.8 to 3.2.10 #​16269
  • Bump org.springframework:spring-framework-bom from 6.1.15 to 6.1.16 #​16272

🔩 Build Updates

  • Bump antora from 3.2.0-alpha.6 to 3.2.0-alpha.8 in /docs #​16244
  • Update Antora UI Spring to v0.4.18 #​16110

❤️ Contributors

Thank you to all the contributors who worked on this release:

@​dependabot[bot], @​github-actions[bot], and @​kse-music

v6.3.5

Compare Source

⭐ New Features

  • Support ServerExchangeRejectedHandler @Bean #​16062
  • Supporting logout+jwt for back-channel logout with spring-webflux #​15702

🪲 Bug Fixes

  • Align DelegatingAuthenticationConverter Constructors #​15949
  • An empty-string bearer token should result in an appropriate HTTP status code #​16036
  • IpAddressMatcher null pointer exception #​15527
  • RequestMatcherDelegatingAuthorizationManager should be post-processable #​15981
  • Support ServerWebExchangeFirewall @Bean #​15991
  • Unhandled exception in CookieRequestCache results in 500 Internal Server Error #​15986
  • Update logout.adoc: Fix Customizing Logout Success Example #​15956

🔨 Dependency Upgrades

  • Bump ch.qos.logback:logback-classic from 1.5.11 to 1.5.12 #​16006
  • Bump com.fasterxml.jackson:jackson-bom from 2.17.2 to 2.17.3 #​16032
  • Bump io.micrometer:micrometer-observation from 1.12.12 to 1.12.13 #​16126
  • Bump io.projectreactor:reactor-bom from 2023.0.11 to 2023.0.12 #​16082
  • Bump org.hsqldb:hsqldb from 2.7.3 to 2.7.4 #​16033
  • Bump org.springframework.data:spring-data-bom from 2024.0.5 to 2024.0.6 #​16125
  • Bump org.springframework.ldap:spring-ldap-core from 3.2.7 to 3.2.8 #​16102
  • Bump org.springframework:spring-framework-bom from 6.1.14 to 6.1.15 #​16101

🔩 Build Updates

  • Bump @antora/collector-extension from 1.0.0-beta.4 to 1.0.0-beta.5 in /docs #​16117
  • Update Antora UI Spring to v0.4.17 #​15930

❤️ Contributors

Thank you to all the contributors who worked on this release:

@​asimuleo, @​dependabot[bot], @​github-actions[bot], and @​kse-music

v6.3.4

Compare Source

🪲 Bug Fixes

  • Annotation expression template processing should not fail on Class parameter types #​15711
  • Disabling credentials erasure on custom AuthenticationManager is not working #​15808
  • Documentation inconsistency in AuthorizationManager's verify method return type #​15822
  • Methods annotated with @PostFilter are processed twice by PostFilterAuthorizationMethodInterceptor #​15676
  • OidcBackChannelLogoutTokenValidator should not construct when missing OIDC Provider Issuer #​15868
  • SecurityJackson2Modules.getModules(): Cannot load module org.springframework.security.cas.jackson2.CasJackson2Module #​15767
  • The additionalParameters array parameter of OAuth2AuthorizationRequest causes the authorizationRequestUri to be incorrect #​15829

🔨 Dependency Upgrades

  • Bump ch.qos.logback:logback-classic from 1.5.10 to 1.5.11 #​15926
  • Bump io.micrometer:micrometer-observation from 1.12.10 to 1.12.11 #​15917
  • Bump io.mockk:mockk from 1.13.12 to 1.13.13 #​15897
  • Bump io.projectreactor:reactor-bom from 2023.0.10 to 2023.0.11 #​15925
  • Bump jakarta.servlet.jsp.jstl:jakarta.servlet.jsp.jstl-api from 3.0.1 to 3.0.2 #​15694
  • Bump org-eclipse-jetty from 11.0.23 to 11.0.24 #​15731
  • Bump org.jfrog.buildinfo:build-info-extractor-gradle from 4.33.21 to 4.33.22 #​15761
  • Bump org.junit:junit-bom from 5.10.4 to 5.10.5 #​15883
  • Bump org.springframework.data:spring-data-bom from 2024.0.4 to 2024.0.5 #​15958
  • Bump org.springframework.ldap:spring-ldap-core from 3.2.6 to 3.2.7 #​15944
  • Bump org.springframework:spring-framework-bom from 6.1.13 to 6.1.14 #​15945

🔩 Build Updates

  • Bump @antora/collector-extension from 1.0.0-beta.2 to 1.0.0-beta.3 in /docs #​15907
  • Bump @springio/asciidoctor-extensions from 1.0.0-alpha.13 to 1.0.0-alpha.14 in /docs #​15836
  • Migrate slack notifications to GChat #​15668
  • Release 6.3.4 #​15964
  • Update eclipse/vscode configuration to use -parameters #​15681

❤️ Contributors

Thank you to all the contributors who worked on this release:

@​dependabot[bot] and @​kse-music

v6.3.3

Compare Source

🪲 Bug Fixes

  • ObservationRegistry is never post-processed #​15658

🔨 Dependency Upgrades

  • Bump org-eclipse-jetty from 11.0.22 to 11.0.23 #​15664

❤️ Contributors

Thank you to all the contributors who worked on this release:

@​dependabot[bot]

v6.3.2

Compare Source

⭐ New Features

  • ActiveDirectoryLdapAuthenticationProvider does not implement support for multiple urls #​15495
  • Document the role of CredentialsContainer #​15321
  • OIDC Backchannel Logout should allow logout tokens having typ header of logout+jwt #​15410

🪲 Bug Fixes

  • A broken link in Spring Security reference #​15297
  • Documentation for ServletBearerExchangeFilterFunction incomplete or incorrect #​15460
  • EnableMethodSecurity should publish only one bean of each AuthorizationAdvisor #​15592
  • Fix Compromised Password Checker Docs Sample Not Working #​15305
  • Fix for #​15172 introduces significant performance degredation #​15324
  • Pre/PostAuthorize should not ignore HandleAuthorizationDenied#handlerClass when ApplicationContext is not provided #​15535
  • Update prerequisites documentation with Java 17 #​15340
  • Use Correct Meta-Annotation in Kotlin Sample #​15472
  • Using sec:authorize in JSPX causes 'java.lang.NullPointerException: Cannot invoke "jakarta.servlet.ServletRegistration.getClassName()" because "registration" is null' #​15440

🔨 Dependency Upgrades

  • Bump ch.qos.logback:logback-classic from 1.5.6 to 1.5.7 #​15619
  • Bump com.fasterxml.jackson:jackson-bom from 2.17.1 to 2.17.2 #​15374
  • Bump com.github.spullara.mustache.java:compiler from 0.9.13 to 0.9.14 #​15373
  • Bump io.micrometer:micrometer-observation from 1.12.7 to 1.12.8 #​15383
  • Bump io.micrometer:micrometer-observation from 1.12.8 to 1.12.9 #​15581
  • Bump io.mockk:mockk from 1.13.11 to 1.13.12 #​15430
  • Bump io.projectreactor:reactor-bom from 2023.0.7 to 2023.0.8 #​15388
  • Bump io.projectreactor:reactor-bom from 2023.0.8 to 2023.0.9 #​15597
  • Bump jakarta.servlet.jsp.jstl:jakarta.servlet.jsp.jstl-api from 3.0.0 to 3.0.1 #​15582
  • Bump org-apache-maven-resolver from 1.9.20 to 1.9.21 #​15372
  • Bump org-apache-maven-resolver from 1.9.21 to 1.9.22 #​15545
  • Bump org-eclipse-jetty from 11.0.21 to 11.0.22 #​15356
  • Bump org.apache.maven:maven-resolver-provider from 3.9.7 to 3.9.8 #​15268
  • Bump org.apache.maven:maven-resolver-provider from 3.9.8 to 3.9.9 #​15642
  • Bump org.gretty:gretty from 4.1.4 to 4.1.5 #​15431
  • Bump org.hibernate.orm:hibernate-core from 6.4.9.Final to 6.4.10.Final #​15530
  • Bump org.jetbrains.kotlin:kotlin-bom from 1.9.24 to 1.9.25 #​15456
  • Bump org.jetbrains.kotlin:kotlin-gradle-plugin from 1.9.24 to 1.9.25 #​15455
  • Bump org.jfrog.buildinfo:build-info-extractor-gradle from 4.33.19 to 4.33.20 #​15267
  • Bump org.junit:junit-bom from 5.10.2 to 5.10.3 #​15315
  • Bump org.skyscreamer:jsonassert from 1.5.1 to 1.5.3 #​15336
  • Bump org.slf4j:slf4j-api from 2.0.13 to 2.0.14 #​15529
  • Bump org.slf4j:slf4j-api from 2.0.14 to 2.0.15 #​15546
  • Bump org.slf4j:slf4j-api from 2.0.15 to 2.0.16 #​15571
  • Bump org.springframework.data:spring-data-bom from 2024.0.1 to 2024.0.2 #​15421
  • Bump org.springframework.data:spring-data-bom from 2024.0.2 to 2024.0.3 #​15643
  • Bump org.springframework.ldap:spring-ldap-core from 3.2.4 to 3.2.6 #​15620
  • Bump org.springframework:spring-framework-bom from 6.1.10 to 6.1.11 #​15402
  • Bump org.springframework:spring-framework-bom from 6.1.11 to 6.1.12 #​15613
  • Bump org.springframework:spring-framework-bom from 6.1.9 to 6.1.10 #​15279

🔩 Build Updates

  • Automate check of expected branch version #​15310
  • Bump @antora/collector-extension from 1.0.0-alpha.4 to 1.0.0-alpha.6 in /docs #​15449
  • Bump @antora/collector-extension from 1.0.0-alpha.6 to 1.0.0-alpha.7 in /docs #​15482
  • Bump @antora/collector-extension from 1.0.0-alpha.7 to 1.0.0-beta.1 in /docs #​15560
  • Bump @antora/collector-extension from 1.0.0-beta.1 to 1.0.0-beta.2 in /docs #​15637
  • Bump @springio/antora-extensions from 1.11.1 to 1.12.0 in /docs #​15418
  • Bump @springio/antora-extensions from 1.12.0 to 1.13.0 in /docs #​15517
  • Bump @springio/antora-extensions from 1.13.0 to 1.13.1 in /docs #​15561
  • Bump @springio/antora-extensions from 1.13.1 to 1.14.2 in /docs #​15636
  • Bump @springio/asciidoctor-extensions from 1.0.0-alpha.10 to 1.0.0-alpha.11 in /docs #​15419
  • Bump @springio/asciidoctor-extensions from 1.0.0-alpha.11 to 1.0.0-alpha.12 in /docs #​15515
  • Bump antora from 3.2.0-alpha.4 to 3.2.0-alpha.5 in /docs #​15329
  • Bump antora from 3.2.0-alpha.5 to 3.2.0-alpha.6 in /docs #​15480
  • Bump com.gradle.develocity from 3.17.5 to 3.17.6 #​15464
  • Bump io-spring-javaformat from 0.0.42 to 0.0.43 #​15650
  • Fix typos and formatting in documentation #​15380
  • Migrate slack notifications to GChat #​15505
  • Use explicit types instead of var #​15537

❤️ Contributors

Thank you to all the contributors who worked on this release:

@​Kehrlann, @​dependabot[bot], and @​tahakorkem

v6.3.1

Compare Source

⭐ New Features

  • Clarify the behavior of Concurrent Session Management when an IdP is involved #​15071
  • Mention all required dependencies in LDAP documentation #​15245
  • Minor docs fix #​15144

🪲 Bug Fixes

  • AbstractRequestMatcherRegistry#requestMatchers should pick MvcRequestMatcher when using MockMvc #​15211
  • Assert WebSession is not null #​15179
  • DispatcherServletDelegatingRequestMatcher causes errors when running tests with MockMvc #​15197
  • Documentation clarification after #​12783 has been closed is needed. #​15208
  • Fix Java example in multitenanci.adoc #​15151
  • Fix Kotlin example in authorize-http-requests.adoc #​15129
  • Incorrect documentation for OIDC Back-Channel Logout #​15212
  • IpAddressMatcher.matches(String address) still accepts URLs #​15172
  • LDIF file on official documentation breaks the startup process #​15167
  • Link to article with remember-me-persistent-token strategy is broken #​15149
  • OpenSaml4AssertionValidator is not respecting clock skew settings #​15183
  • Resolving invalid CSRF token values is not consistent #​15186
  • spring-security/docs/modules/ROOT/pages/servlet/authorization /method-security #​15143
  • SpringOpaqueTokenIntrospector does not add scopes as granted authorities properly #​15165

🔨 Dependency Upgrades

  • Bump io.micrometer:micrometer-observation from 1.12.6 to 1.12.7 #​15225
  • Bump io.projectreactor:reactor-bom from 2023.0.6 to 2023.0.7 #​15229
  • Bump org.apache.directory.shared:shared-ldap from 0.9.15 to 0.9.19 #​15161
  • Bump org.apache.maven:maven-resolver-provider from 3.9.6 to 3.9.7 #​15168
  • Bump org.gretty:gretty from 4.1.3 to 4.1.4 #​15133
  • Bump org.hibernate.orm:hibernate-core from 6.4.8.Final to 6.4.9.Final #​15228
  • Bump org.hsqldb:hsqldb from 2.7.2 to 2.7.3 #​15193
  • Bump org.springframework.data:spring-data-bom from 2024.0.0 to 2024.0.1 #​15260
  • Bump org.springframework.ldap:spring-ldap-core from 3.2.3 to 3.2.4 #​15251
  • Bump org.springframework:spring-framework-bom from 6.1.7 to 6.1.8 #​15134
  • Bump org.springframework:spring-framework-bom from 6.1.8 to 6.1.9 #​15252

🔩 Build Updates

  • Bump @antora/collector-extension from 1.0.0-alpha.3 to 1.0.0-alpha.4 in /docs #​15159
  • Bump @springio/antora-extensions from 1.10.0 to 1.11.1 in /docs #​15141
  • Bump com.gradle.develocity from 3.17.4 to 3.17.5 #​15239
  • Bump gradle/gradle-build-action from 2 to 3 #​15157
  • Bump io-spring-javaformat from 0.0.41 to 0.0.42 #​15219
  • Bump org.jfrog.buildinfo:build-info-extractor-gradle from 4.33.15 to 4.33.16 #​15176
  • Bump org.jfrog.buildinfo:build-info-extractor-gradle from 4.33.16 to 4.33.17 #​15218
  • Bump org.jfrog.buildinfo:build-info-extractor-gradle from 4.33.17 to 4.33.19 #​15261
  • Bump spring-io/spring-doc-actions from 17ed79e to 5a57bcc #​15139

❤️ Contributors

Thank you to all the contributors who worked on this release:

@​dependabot[bot] and @​theHacker

v6.3.0

Compare Source

⭐ New Features
  • Add getters to OAuth2AuthorizedClientId #​13648
  • Add timeout defaults to JwtDecoders #​14890
  • doc: added hint to declare GrantedAuthorityDefaults as infrastructure bean #​15065
  • Improve logging for Global Authentication #​14711
  • Minor docs fix #​15043
  • Minor Documentation update on import needed for using Kotlin DSL #​14969
  • OAuth2 Client Authentication docs are incomplete #​14982
  • Proofread CasAuthenticationFilter documentation #​14883
  • Replace "Spring Boot 2.x" with "Spring Boot" #​14919
  • Simplify Disabling application/x-www-form-urlencoded Encoding Client ID and Secret #​14859
  • Support Specifying Identifier for relying-party-registrations Element #​14487
  • Update What's New in 6.3 #​14918
🪲 Bug Fixes
  • Do Not Invalidate Current Session When Its Registered #​15066
  • Fix MethodAuthorizationDeniedPostProcessor does not exist in java doc #​14955
  • fix docs error in AuthenticatedReactiveAuthorizationManager #​14979
  • OIDC Logout section is not shown in the navbar #​15113
  • Wrong information for RequestCacheAwareFilter in the Spring Security documentation. #​14996
🔨 Dependency Upgrades
  • Bump ch.qos.logback:logback-classic from 1.5.5 to 1.5.6 #​14926
  • Bump com.fasterxml.jackson:jackson-bom from 2.17.0 to 2.17.1 #​15010
  • Bump com.gradle.develocity from 3.17.2 to 3.17.3 #​15051
  • Bump com.gradle.develocity from 3.17.3 to 3.17.4 #​15104
  • Bump io.micrometer:micrometer-observation from 1.12.5 to 1.12.6 #​15068
  • Bump io.mockk:mockk from 1.13.10 to 1.13.11 #​15086
  • Bump io.projectreactor:reactor-bom from 2023.0.5 to 2023.0.6 #​15076
  • Bump org-apache-maven-resolver from 1.9.18 to 1.9.19 #​14940
  • Bump org-apache-maven-resolver from 1.9.19 to 1.9.20 #​14987
  • Bump org-aspectj from 1.9.22 to 1.9.22.1 #​15052
  • Bump org-bouncycastle from 1.78 to 1.78.1 #​14929
  • Bump org-eclipse-jetty from 11.0.20 to 11.0.21 #​15087
  • Bump org.hibernate.orm:hibernate-core from 6.4.4.Final to 6.4.5.Final #​14948
  • Bump org.hibernate.orm:hibernate-core from 6.4.5.Final to 6.4.6.Final #​14952
  • Bump org.hibernate.orm:hibernate-core from 6.4.6.Final to 6.4.7.Final #​14962
  • Bump org.hibernate.orm:hibernate-core from 6.4.7.Final to 6.4.8.Final #​14980
  • Bump org.jetbrains.kotlin:kotlin-bom from 1.9.23 to 1.9.24 #​15025
  • Bump org.jetbrains.kotlin:kotlin-gradle-plugin from 1.9.23 to 1.9.24 #​15026
  • Bump org.jetbrains.kotlinx:kotlinx-coroutines-bom from 1.8.0 to 1.8.1 #​15053
  • Bump org.jfrog.buildinfo:build-info-extractor-gradle from 4.33.13 to 4.33.15 #​14945
  • Bump org.springframework.data:spring-data-bom from 2024.0.0-RC1 to 2024.0.0 #​15103
  • Bump org.springframework:spring-framework-bom from 6.1.6 to 6.1.7 #​15088
🔩 Build Updates
  • Attach Antora Docs to Pull Requests #​15061
  • Bump com.github.spullara.mustache.java:compiler from 0.9.11 to 0.9.12 #​14986
  • Bump com.github.spullara.mustache.java:compiler from 0.9.12 to 0.9.13 #​14999
  • Bump io.spring.ge.conventions from 0.0.16 to 0.0.17 #​14963
  • Bump io.spring.gradle:spring-security-release-plugin from 1.0.2 to 1.0.3 #​14928
  • Consider Adding a Build Updates section to the release changelog #​15039
❤️ Contributors

Thank you to all the contributors who worked on this release:

@​Crain-32, @​Kehrlann, @​MrJovanovic13, @​ch4mpy, @​dependabot[bot], @​joaquinjsb, @​kse-music, @​madorb, @​rishiraj88, and @​vvaadd

v6.2.8

Compare Source

⭐ New Features
  • Support ServerExchangeRejectedHandler @Bean #​16061
  • Support ServerWebExchangeFirewall @Bean #​15987
🪲 Bug Fixes
  • Fix error when Bearer token is requested with empty string #​15940
  • Make RequestMatcherDelegatingAuthorizationManager post-processable #​15978
  • RequestMatcherDelegatingAuthorizationManager should be post-processable #​15948
  • Unhandled exception in CookieRequestCache results in 500 Internal Server Error #​15985
🔨 Dependency Upgrades
  • Bump io.micrometer:micrometer-observation from 1.12.12 to 1.12.13 #​16128
  • Bump io.projectreactor:reactor-bom from 2023.0.11 to 2023.0.12 #​16081
  • Bump org.hsqldb:hsqldb from 2.7.3 to 2.7.4 #​16031
  • Bump org.springframework.data:spring-data-bom from 2023.1.11 to 2023.1.12 #​16127
  • Bump org.springframework.ldap:spring-ldap-core from 3.2.7 to 3.2.8 #​16100
  • Bump org.springframework:spring-framework-bom from 6.1.14 to 6.1.15 #​16099
🔩 Build Updates
  • Bump @antora/collector-extension from 1.0.0-beta.4 to 1.0.0-beta.5 in /docs #​16120
  • Update Antora UI Spring to v0.4.17 #​15931
❤️ Contributors

Thank you to all the contributors who worked on this release:

@​codeconsole, @​dependabot[bot], @​github-actions[bot], and @​jacknie84

v6.2.7

Compare Source

🪲 Bug Fixes
  • Disabling credentials erasure on custom AuthenticationManager is not working #​15807
  • Documentation inconsistency in AuthorizationManager's verify method return type #​15704
  • Fix code format in OIDC Logout docs #​15566
  • Fix OIDC Logout docs: Session Strategy vs. Registry #​15686
  • Methods annotated with @PostFilter are processed twice by PostFilterAuthorizationMethodInterceptor #​15675
  • Methods annotated with @PostFilter are processed twice by PostFilterAuthorizationMethodInterceptor #​15651
  • SecurityJackson2Modules.getModules(): Cannot load module org.springframework.security.cas.jackson2.CasJackson2Module [#​15766](https://redirect.github.com/spring-projects/spring-security/issues

Configuration

📅 Schedule: Branch creation - At any time (no schedule defined), Automerge - At any time (no schedule defined).

🚦 Automerge: Disabled by config. Please merge this manually once you are satisfied.

Rebasing: Whenever PR is behind base branch, or you tick the rebase/retry checkbox.

🔕 Ignore: Close this PR and you won't be reminded about this update again.


  • If you want to rebase/retry this PR, check this box

This PR was generated by Mend Renovate. View the repository job log.

@renovate renovate bot requested a review from a team as a code owner November 21, 2022 17:38
@renovate renovate bot force-pushed the renovate/major-spring-security branch from f10c94f to eb813d6 Compare December 7, 2022 17:12
@renovate renovate bot force-pushed the renovate/major-spring-security branch from eb813d6 to bdabc1d Compare December 19, 2022 19:09
@renovate renovate bot force-pushed the renovate/major-spring-security branch from bdabc1d to 92a339d Compare March 12, 2023 17:58
@renovate renovate bot force-pushed the renovate/major-spring-security branch from 92a339d to 437af7b Compare May 29, 2023 21:47
@renovate renovate bot force-pushed the renovate/major-spring-security branch from 437af7b to 3dc2acb Compare June 19, 2023 18:25
@renovate renovate bot force-pushed the renovate/major-spring-security branch from 3dc2acb to c36dfa3 Compare July 17, 2023 23:05
@renovate renovate bot changed the title Update spring security to v6 (major) Update dependency org.springframework.security:spring-security-web to v6 Jul 31, 2023
@renovate renovate bot force-pushed the renovate/major-spring-security branch from c36dfa3 to aea0e78 Compare August 21, 2023 19:14
@renovate renovate bot force-pushed the renovate/major-spring-security branch from aea0e78 to cdd3777 Compare September 18, 2023 17:09
@renovate renovate bot force-pushed the renovate/major-spring-security branch 2 times, most recently from d43a6f2 to ec42645 Compare October 16, 2023 16:17
@renovate renovate bot force-pushed the renovate/major-spring-security branch from ec42645 to c439cf1 Compare October 26, 2023 14:51
@renovate renovate bot changed the title Update dependency org.springframework.security:spring-security-web to v6 Update spring security to v6 (major) Oct 26, 2023
@renovate renovate bot force-pushed the renovate/major-spring-security branch from c439cf1 to b0c8d11 Compare October 27, 2023 07:08
@renovate renovate bot force-pushed the renovate/major-spring-security branch from b0c8d11 to 6c27e05 Compare November 20, 2023 17:21
@renovate renovate bot force-pushed the renovate/major-spring-security branch from 6c27e05 to 795ec8b Compare December 18, 2023 19:15
@renovate renovate bot force-pushed the renovate/major-spring-security branch from 795ec8b to aaf1788 Compare February 8, 2024 08:17
@renovate renovate bot force-pushed the renovate/major-spring-security branch from aaf1788 to 2d2a544 Compare February 16, 2024 22:25
@renovate renovate bot force-pushed the renovate/major-spring-security branch from 2d2a544 to 0e76cbb Compare March 18, 2024 14:25
@renovate renovate bot force-pushed the renovate/major-spring-security branch from 0e76cbb to e1e363f Compare April 15, 2024 18:33
@renovate renovate bot force-pushed the renovate/major-spring-security branch from e1e363f to 4185aed Compare May 20, 2024 19:21
@renovate renovate bot force-pushed the renovate/major-spring-security branch from 4185aed to b356966 Compare June 17, 2024 20:08
@renovate renovate bot force-pushed the renovate/major-spring-security branch 2 times, most recently from 5f919fb to c698059 Compare August 21, 2024 20:55
@renovate renovate bot force-pushed the renovate/major-spring-security branch from c698059 to 597b9ba Compare October 21, 2024 20:27
@renovate renovate bot changed the title Update spring security to v6 (major) Update dependency org.springframework.security:spring-security-config to v6 Oct 28, 2024
@renovate renovate bot force-pushed the renovate/major-spring-security branch 2 times, most recently from bcfd480 to 1f49e4e Compare November 21, 2024 05:17
@renovate renovate bot force-pushed the renovate/major-spring-security branch from 1f49e4e to c7ca2ad Compare December 16, 2024 19:46
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

Successfully merging this pull request may close these issues.

0 participants