Skip to content

fix(deps): update dependency org.springframework.security:spring-security-test to v6.4.5 #100

New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Open
wants to merge 1 commit into
base: main
Choose a base branch
from

Conversation

renovate[bot]
Copy link
Contributor

@renovate renovate bot commented Apr 15, 2024

This PR contains the following updates:

Package Change Age Adoption Passing Confidence
org.springframework.security:spring-security-test (source) 6.2.3 -> 6.4.5 age adoption passing confidence

Release Notes

spring-projects/spring-security (org.springframework.security:spring-security-test)

v6.4.5

Compare Source

⭐ New Features

  • Add link to docs zip file to the reference #​16799
  • Fix attribute name in http.adoc #​16784
  • Update ServerOAuth2AuthorizedClientExchangeFilterFunction javadoc #​16783

🪲 Bug Fixes

  • [Docs] Broken link on Spring MVC Test Integration page #​16785
  • ServerBearerTokenAuthenticationConverter validates parameters when not enabled #​16901
  • Clarify WebInvocationPrivilegeEvaluator JavaDoc #​16782
  • CookieServerCsrfTokenRepository.withHttpOnlyFalse() ineffective if setCookieCustomizer() is used #​16862
  • Correct closing tag in default PassKey HTML form #​16601
  • Fix WebAuthn saves Anonymous PublicKeyCredentialUserEntity #​16606
  • OpenSaml support should preserve encrypted elements for further analysis #​16367
  • Sorting in AuthorizationAdvisorProxyFactory should be thread-safe #​16837
  • WebFlux reference links to Servlet docs #​16786
  • XML config does not apply request-handler-ref to CsrfAuthenticationStrategy #​16844

🔨 Dependency Upgrades

  • Bump ch.qos.logback:logback-classic from 1.5.17 to 1.5.18 #​16767
  • Bump io.micrometer:micrometer-observation from 1.14.5 to 1.14.6 #​16938
  • Bump io.projectreactor:reactor-bom from 2023.0.16 to 2023.0.17 #​16944
  • Bump io.spring.gradle:spring-security-release-plugin from 1.0.3 to 1.0.4 #​16919
  • Bump org-aspectj from 1.9.22.1 to 1.9.24 #​16928
  • Bump org-eclipse-jetty from 11.0.24 to 11.0.25 #​16758
  • Bump org.hibernate.orm:hibernate-core from 6.6.12.Final to 6.6.13.Final #​16895
  • Bump org.springframework.ldap:spring-ldap-core from 3.2.11 to 3.2.12 #​16960
  • Bump org.springframework:spring-framework-bom from 6.2.5 to 6.2.6 #​16959

🔩 Build Updates

  • Bump spring-io/spring-doc-actions from 0.0.19 to 0.0.20 #​16894
  • Release 6.4.5 #​16972

❤️ Contributors

Thank you to all the contributors who worked on this release:

@​AB-xdev, @​Borghii, and @​dependabot[bot]

v6.4.4

Compare Source

🪲 Bug Fixes

  • Add testRuntimeOnly junit-platform-launcher #​16756
  • Align Method Traversal Algorithm with Spring Framework #​16751
  • Disable Flaky WebAuthnWebDriverTests #​16753
  • Fix @PostResult example in method-security doc #​16628
  • Grammar Fixes in OAuth 2.0 JavaDoc #​16619

🔨 Dependency Upgrades

  • Bump ch.qos.logback:logback-classic from 1.5.16 to 1.5.17 #​16649
  • Bump com.fasterxml.jackson:jackson-bom from 2.18.2 to 2.18.3 #​16692
  • Bump com.webauthn4j:webauthn4j-core from 0.28.5.RELEASE to 0.28.6.RELEASE #​16691
  • Bump io.micrometer:micrometer-observation from 1.14.4 to 1.14.5 #​16715
  • Bump io.mockk:mockk from 1.13.16 to 1.13.17 #​16675
  • Bump io.projectreactor:reactor-bom from 2023.0.15 to 2023.0.16 #​16725
  • Bump org.hibernate.orm:hibernate-core from 6.6.10.Final to 6.6.11.Final #​16748
  • Bump org.jfrog.buildinfo:build-info-extractor-gradle from 4.33.23 to 4.33.24 #​16669
  • Bump org.slf4j:slf4j-api from 2.0.16 to 2.0.17 #​16650
  • Bump org.springframework.data:spring-data-bom from 2024.1.3 to 2024.1.4 #​16749
  • Bump org.springframework:spring-framework-bom from 6.2.3 to 6.2.4 #​16733

❤️ Contributors

Thank you to all the contributors who worked on this release:

@​Kuba15, @​dependabot[bot], and @​pat-mccusker

v6.4.3

Compare Source

⭐ New Features

  • Add Support disableDefaultRegistrationPage to WebAuthnDsl #​16395

🪲 Bug Fixes

  • withValue used incorrectly #​16527
  • Fix for JdbcOneTimeTokenService cleanupExpiredTokens failing with PostgreSQL #​16344
  • Fix GenerateOneTimeTokenWebFilter double publish of chain.filter(...) #​16459
  • Fix Kotlin DSL webAuthn { } #​16338
  • Fix loader has changed while resolving nodes in WebAuthnWebDriverTests #​16463
  • Fix logoutRequestRepository not set on Saml2RelyingPartyInitiatedLogoutSuccessHandler #​16310
  • Implement Serializable for WebAuthnAuthentication #​16285
  • Make AuthorizationDecision Serializable #​16544
  • Make PublicKeyCredentialRequestOptions Serializable Backport #​16584
  • Make Saml2AuthenticationToken Serializable #​16287
  • Make WebAuthnAuthentication Serializable #​16273
  • Make WebAuthnAuthenticationRequestToken Serializable #​16602
  • Make WebAuthnAuthenticationTokenRequest Serializable #​16481
  • Misconfigured OAuth2LoginAuthenticationFilter when combining OAuth2 login and OAuth2 client configuration #​16466
  • OTT Should Use non-static member to capture the last OneTimeToken #​16471
  • webauthn js should ensure allowCredentials[].id is an ArrayBuffer #​16440

🔨 Dependency Upgrades

  • Bump ch.qos.logback:logback-classic from 1.5.15 to 1.5.16 #​16364
  • Bump com.nimbusds:oauth2-oidc-sdk from 9.43.5 to 9.43.6 #​16598
  • Bump com.webauthn4j:webauthn4j-core from 0.28.4.RELEASE to 0.28.5.RELEASE #​16523
  • Bump io.micrometer:micrometer-observation from 1.14.3 to 1.14.4 #​16565
  • Bump io.mockk:mockk from 1.13.14 to 1.13.16 #​16399
  • Bump io.projectreactor:reactor-bom from 2023.0.14 to 2023.0.15 #​16576
  • Bump io.rsocket:rsocket-bom from 1.1.4 to 1.1.5 #​16534
  • Bump org.hibernate.orm:hibernate-core from 6.6.7.Final to 6.6.8.Final #​16610
  • Bump org.junit:junit-bom from 5.11.3 to 5.11.4 #​16292
  • Bump org.springframework.data:spring-data-bom from 2024.1.2 to 2024.1.3 #​16611
  • Bump org.springframework.ldap:spring-ldap-core from 3.2.10 to 3.2.11 #​16597
  • Bump org.springframework:spring-framework-bom from 6.2.2 to 6.2.3 #​16599
  • Update to oauth2-oidc-sdk 9.43.5 #​16583

🔩 Build Updates

❤️ Contributors

Thank you to all the contributors who worked on this release:

@​Kehrlann, @​NeoTraveler, @​dependabot[bot], @​franticticktick, @​making, and @​ngocnhan-tran1996

v6.4.2

Compare Source

⭐ New Features

  • Add 6.4 Sample Serializations for Serializable classes #​16274
  • Add @inheritDoc to sessionIdChanged method #​16216
  • Fix typo in oauth2 resource server documentation #​16053
  • Fixed confusing phrasing in the docs for a better clarity. #​16169
  • Improve AuthorizationManager configuration error messages #​16194
  • Polish #​16148
  • Use Documentation Tags for Maven and Gradle in Getting Started #​16234
  • Add WebDriver WebAuthn test #​15969

🪲 Bug Fixes

  • Add Deprecated ObjectPostProcessor constructor #​16212
  • Add RuntimeHints for webauthn Javascript resource #​16159
  • Always return current ClientRegistration in loadAuthorizedClient #​16139
  • Avoid requesting an unnecessary attestation statement when creating a webauthn credential #​16252
  • CI is not using the correct secret for Develocity #​16263
  • Dark mode rendering issue with images on CSRF and Method Security pages #​16176
  • DefaultSaml2AuthenticatedPrincipal should define a serialVersionUID #​16163
  • Delay initialization of AuthenticationProvider in Global Authentication #​16147
  • Fix Documentation Typos #​16054
  • Correct OAuth2ClientHttpRequestInterceptor Usage Documentation #​16172
  • Fix Typo in 'What's New' Documentation #​16183
  • Fix WebAuthnWebdriverTests #​16279
  • Correct OpenSAML 5.x Documentation #​16195
  • Issue when using @AuthenticationPrincipal on interfaces #​16177
  • Mutate breaks functionality of StrictFirewallHttpHeaders with recently modified HttpHeaders#writabeHttpHeaders #​16261
  • Remove duplicate cache in AuthenticationPrincipalArgumentResolverand CurrentSecurityContextArgumentResolver #​16202
  • Resolve ObjectPostProcessor collisions between RSocket and WebFlux security configuration #​16161
  • Restore @AuthenticationPrincipal/@CurrentSecurityContext Interface Support #​16245
  • Restore Servlet 5 Compatiblity for CookieCsrfTokenRepository #​16220
  • Spelling error in opensaml.adoc #​16146
  • Update document regarding PublicKeyCredentialCreationOptions.attestation value #​16264
  • Verification Options Should Return Saved Transports for Credentials #​16084

🔨 Dependency Upgrades

  • Bump com.fasterxml.jackson:jackson-bom from 2.18.1 to 2.18.2 #​16184
  • Bump com.webauthn4j:webauthn4j-core from 0.28.2.RELEASE to 0.28.3.RELEASE #​16203
  • Bump io.micrometer:micrometer-observation from 1.14.1 to 1.14.2 #​16255
  • Bump io.projectreactor:reactor-bom from 2023.0.12 to 2023.0.13 #​16256
  • Bump org.gradle.wrapper-upgrade from 0.11.4 to 0.12 #​16209
  • Bump org.gretty:gretty from 4.1.5 to 4.1.6 #​16247
  • Bump org.hibernate.orm:hibernate-core from 6.6.2.Final to 6.6.3.Final #​16145
  • Bump org.htmlunit:htmlunit from 4.6.0 to 4.7.0 #​16205
  • Bump org.jfrog.buildinfo:build-info-extractor-gradle from 4.33.22 to 4.33.23 #​16180
  • Bump org.seleniumhq.selenium:htmlunit3-driver from 4.26.0 to 4.27.0 #​16204
  • Bump org.seleniumhq.selenium:selenium-java from 4.26.0 to 4.27.0 #​16167
  • Bump org.springframework.data:spring-data-bom from 2024.1.0 to 2024.1.1 #​16290
  • Bump org.springframework.ldap:spring-ldap-core from 3.2.8 to 3.2.10 #​16270
  • Bump org.springframework:spring-framework-bom from 6.2.0 to 6.2.1 #​16271

🔩 Build Updates

  • Bump @antora/collector-extension from 1.0.0 to 1.0.1 in /docs #​16239
  • Bump antora from 3.2.0-alpha.6 to 3.2.0-alpha.8 in /docs #​16237
  • Bump gradle/gradle-build-action from 2 to 3 #​16278
  • Remove 5.8.x and 6.2.x dependabot configuration #​16268
  • Remove 5.8.x from Auto Merge Forward Dependabot PRs #​15770

❤️ Contributors

Thank you to all the contributors who worked on this release:

@​12OneTwo12, @​Kehrlann, @​MuhammadNFadhil, @​OrangeDog, @​Spikhalskiy, @​dependabot[bot], @​harpreets789, @​kse-music, @​martin-tarjanyi, @​ngocnhan-tran1996, and @​ynojima

v6.4.1

Compare Source

🪲 Bug Fixes

  • Documentation images should render clearly in both light and dark mode #​16132
  • Fix conflicting bean names between @EnableWebSecurity and @EnableWebSocketSecurity #​16113

🔩 Build Updates

  • Update Antora UI Spring to v0.4.18 #​16112

❤️ Contributors

Thank you to all the contributors who worked on this release:

@​github-actions[bot] and @​ngocnhan-tran1996

v6.4.0

Compare Source

⭐ New Features

  • Add @FunctionalInterface to AuthorizationEventPublisher #​15934
  • Add DefaultResourcesFilter.webauthn() #​15970
  • Add deprecation notice for missing leading slashes #​16020
  • Code Cleanup #​15996
  • Document passkeys dependencies #​16107
  • Factor out some common object mocking in tests #​15396
  • Fix saml2 authentication guide docs #​16017
  • Improve documentation about CredentialsContainer #​15554
  • Improve Documentation on Adding a Custom Security Filter #​15893
  • Improve Error Message for Conflicting Filter Chains #​15992
  • Make it easier to determine where a filter chain has been defined #​15874
  • OIDC logout not working for JPA/JDBC OAuth2AuthorizationService because DefaultSaml2AuthenticatedPrincipal does not implement equality #​15346
  • Polish JdbcOneTimeTokenService #​15997
  • relying-party-registration doesn't allow placeholders in xml #​14645
  • Remove unnecessary parentheses and add static final field MockPortResolver#getServerPort #​15875
  • Support ServerExchangeRejectedHandler @Bean #​16063

🪲 Bug Fixes

  • An empty-string bearer token should result in an appropriate HTTP status code #​16037
  • AuthorizeReturnObject AOT support should register proxied class as well #​16106
  • Correct class name reference in WebFilterChainProxy JavaDoc #​16004
  • Fix typo javadoc some classes #​16022
  • Initialize OpenSAML in OpenSamlAssertingPartyMetadataRepository #​16055
  • IpAddressMatcher null pointer exception #​16104
  • OpenSamlAssertingPartyMetadataRepository should initialize OpenSAML #​16042
  • Support ServerWebExchangeFirewall @Bean #​15999
  • UniqueSecurityAnnotationScanner throws ConcurrentModificationException #​15906

🔨 Dependency Upgrades

  • Bump ch.qos.logback:logback-classic from 1.5.11 to 1.5.12 #​16005
  • Bump com.fasterxml.jackson:jackson-bom from 2.18.0 to 2.18.1 #​16007
  • Bump com.webauthn4j:webauthn4j-core from 0.28.1.RELEASE to 0.28.2.RELEASE #​16122
  • Bump io.freefair.gradle:aspectj-plugin from 8.10.2 to 8.11 #​16123
  • Bump io.micrometer:micrometer-observation from 1.14.0 to 1.14.1 #​16121
  • Bump io.projectreactor:reactor-bom from 2023.0.11 to 2023.0.12 #​16079
  • Bump org-bouncycastle from 1.78.1 to 1.79 #​16010
  • Bump org.hibernate.orm:hibernate-core from 6.6.1.Final to 6.6.2.Final #​16048
  • Bump org.hsqldb:hsqldb from 2.7.3 to 2.7.4 #​16028
  • Bump org.htmlunit:htmlunit from 4.5.0 to 4.6.0 #​16044
  • Bump org.junit:junit-bom from 5.11.2 to 5.11.3 #​15968
  • Bump org.seleniumhq.selenium:htmlunit3-driver from 4.25.0 to 4.26.0 #​16043
  • Bump org.seleniumhq.selenium:selenium-java from 4.25.0 to 4.26.0 #​16018
  • Bump org.springframework.data:spring-data-bom from 2024.0.5 to 2024.1.0 #​16124
  • Bump org.springframework.ldap:spring-ldap-core from 3.2.7 to 3.2.8 #​16097
  • Bump org.springframework:spring-framework-bom from 6.2.0-RC3 to 6.2.0 #​16096

🔩 Build Updates

  • Bump @antora/collector-extension from 1.0.0-beta.4 to 1.0.0-beta.5 in /docs #​16115
  • Update Antora UI Spring to v0.4.17 #​15929

❤️ Contributors

Thank you to all the contributors who worked on this release:

@​Chu3laMan, @​Kehrlann, @​Limm-jk, @​dcolazin, @​dependabot[bot], @​franticticktick, @​github-actions[bot], @​gzhao9, @​ig-jinwoo, @​jzheaux, @​kse-music, @​ngocnhan-tran1996, and @​nomoreFt

v6.3.9

Compare Source

⭐ New Features

  • Add link to docs zip file to the reference #​16798
  • Clarify WebInvocationPrivilegeEvaluator JavaDoc #​16548
  • Fix attribute name in http.adoc #​16776
  • Fix Spring Framework reference link #​16718
  • Fix WebFlux authentication reference link #​16719
  • Update ServerOAuth2AuthorizedClientExchangeFilterFunction javadoc #​16555

🪲 Bug Fixes

  • Do not validate parameters in ServerBearerTokenAuthenticationConverter and DefaultBearerTokenResolver if not enabled #​16039
  • Fix the request matcher patterns in the documentation #​16713
  • setCookieCustomizer should not reset withHttpOnlyFalse httpOnly setting #​16822
  • Sorting in AuthorizationAdvisorProxyFactory should be thread-safe #​16834
  • Use correct message prompt in AuthorizeReturnObjectMethodInterceptor constructor #​16829
  • XML config does not apply request-handler-ref to CsrfAuthenticationStrategy #​16801

🔨 Dependency Upgrades

  • Bump ch.qos.logback:logback-classic from 1.5.17 to 1.5.18 #​16769
  • Bump io.projectreactor:reactor-bom from 2023.0.16 to 2023.0.17 #​16942
  • Bump io.spring.gradle:spring-security-release-plugin from 1.0.3 to 1.0.4 #​16916
  • Bump org-aspectj from 1.9.22.1 to 1.9.24 #​16927
  • Bump org-eclipse-jetty from 11.0.24 to 11.0.25 #​16759
  • Bump org.springframework.ldap:spring-ldap-core from 3.2.11 to 3.2.12 #​16957
  • Bump org.springframework:spring-framework-bom from 6.1.18 to 6.1.19 #​16958

🔩 Build Updates

  • Bump @springio/asciidoctor-extensions from 1.0.0-alpha.16 to 1.0.0-alpha.17 in /docs #​16809
  • Release 6.3.9 #​16973

❤️ Contributors

Thank you to all the contributors who worked on this release:

@​Bragolgirith, @​dependabot[bot], @​jonah1und1, @​kse-music, and @​ngocnhan-tran1996

v6.3.8

Compare Source

🪲 Bug Fixes

  • Add testRuntimeOnly junit-platform-launcher #​16755
  • Fix typo security-api-url attribute in faq.adoc #​16633
  • Security SpEL Expressions Should Propagate AuthorizationDeniedException from Proxied Objects #​16697

🔨 Dependency Upgrades

  • Bump ch.qos.logback:logback-classic from 1.5.16 to 1.5.17 #​16651
  • Bump io.mockk:mockk from 1.13.16 to 1.13.17 #​16676
  • Bump io.projectreactor:reactor-bom from 2023.0.15 to 2023.0.16 #​16724
  • Bump org.jfrog.buildinfo:build-info-extractor-gradle from 4.33.23 to 4.33.24 #​16670
  • Bump org.slf4j:slf4j-api from 2.0.16 to 2.0.17 #​16652
  • Bump org.springframework.data:spring-data-bom from 2024.0.9 to 2024.0.10 #​16747
  • Bump org.springframework:spring-framework-bom from 6.1.17 to 6.1.18 #​16735

🔩 Build Updates

  • Bump @springio/antora-extensions from 1.14.2 to 1.14.4 in /docs #​16637

❤️ Contributors

Thank you to all the contributors who worked on this release:

@​dependabot[bot] and @​ngocnhan-tran1996

v6.3.7

Compare Source

⭐ New Features

  • Improve Stability of S101 CI Task #​16482

🪲 Bug Fixes

  • Fix logoutRequestRepository not set on Saml2RelyingPartyInitiatedLogoutSuccessHandler #​16093
  • Misconfigured OAuth2LoginAuthenticationFilter when combining OAuth2 login and OAuth2 client configuration #​16105

🔨 Dependency Upgrades

  • Bump ch.qos.logback:logback-classic from 1.5.15 to 1.5.16 #​16363
  • Bump com.nimbusds:oauth2-oidc-sdk from 9.43.5 to 9.43.6 #​16594
  • Bump io.mockk:mockk from 1.13.14 to 1.13.16 #​16400
  • Bump io.projectreactor:reactor-bom from 2023.0.14 to 2023.0.15 #​16577
  • Bump io.rsocket:rsocket-bom from 1.1.4 to 1.1.5 #​16533
  • Bump org.springframework.data:spring-data-bom from 2024.0.8 to 2024.0.9 #​16607
  • Bump org.springframework.ldap:spring-ldap-core from 3.2.10 to 3.2.11 #​16595
  • Bump org.springframework:spring-framework-bom from 6.1.16 to 6.1.17 #​16596
  • Update to oauth2-oidc-sdk 9.43.5 #​16582

🔩 Build Updates

  • Bump @springio/asciidoctor-extensions from 1.0.0-alpha.14 to 1.0.0-alpha.16 in /docs #​16519
  • Troubleshoot missing GChat notifications #​16423

❤️ Contributors

Thank you to all the contributors who worked on this release:

@​dependabot[bot] and @​sawprogramming

v6.3.6

Compare Source

🪲 Bug Fixes

  • Always return current ClientRegistration in loadAuthorizedClient #​16138
  • CI is not using the correct secret for Develocity #​16262
  • Dark mode rendering issue with images on CSRF and Method Security pages #​16175
  • Delay initialization AuthenticationProvider in Global Authentication #​16050
  • Do not eagerly construct UserDetailsService bean in Global Authentication #​16144
  • Documentation images should render clearly in both light and dark mode #​16131
  • Mutate breaks functionality of StrictFirewallHttpHeaders with recently modified HttpHeaders#writabeHttpHeaders #​16069
  • OidcBackChannelLogoutWebFilter error response is not a correct JSON #​16229
  • Restore Servlet 5 Compatiblity for CookieCsrfTokenRepository #​16219

🔨 Dependency Upgrades

  • Bump io.projectreactor:reactor-bom from 2023.0.12 to 2023.0.13 #​16257
  • Bump org.gretty:gretty from 4.1.5 to 4.1.6 #​16246
  • Bump org.jfrog.buildinfo:build-info-extractor-gradle from 4.33.22 to 4.33.23 #​16179
  • Bump org.springframework.data:spring-data-bom from 2024.0.6 to 2024.0.7 #​16289
  • Bump org.springframework.ldap:spring-ldap-core from 3.2.8 to 3.2.10 #​16269
  • Bump org.springframework:spring-framework-bom from 6.1.15 to 6.1.16 #​16272

🔩 Build Updates

  • Bump antora from 3.2.0-alpha.6 to 3.2.0-alpha.8 in /docs #​16244
  • Update Antora UI Spring to v0.4.18 #​16110

❤️ Contributors

Thank you to all the contributors who worked on this release:

@​dependabot[bot], @​github-actions[bot], and @​kse-music

v6.3.5

Compare Source

⭐ New Features

  • Support ServerExchangeRejectedHandler @Bean #​16062
  • Supporting logout+jwt for back-channel logout with spring-webflux #​15702

🪲 Bug Fixes

  • Align DelegatingAuthenticationConverter Constructors #​15949
  • An empty-string bearer token should result in an appropriate HTTP status code #​16036
  • IpAddressMatcher null pointer exception #​15527
  • RequestMatcherDelegatingAuthorizationManager should be post-processable #​15981
  • Support ServerWebExchangeFirewall @Bean #​15991
  • Unhandled exception in CookieRequestCache results in 500 Internal Server Error #​15986
  • Update logout.adoc: Fix Customizing Logout Success Example #​15956

🔨 Dependency Upgrades

  • Bump ch.qos.logback:logback-classic from 1.5.11 to 1.5.12 #​16006
  • Bump com.fasterxml.jackson:jackson-bom from 2.17.2 to 2.17.3 #​16032
  • Bump io.micrometer:micrometer-observation from 1.12.12 to 1.12.13 #​16126
  • Bump io.projectreactor:reactor-bom from 2023.0.11 to 2023.0.12 #​16082
  • Bump org.hsqldb:hsqldb from 2.7.3 to 2.7.4 #​16033
  • Bump org.springframework.data:spring-data-bom from 2024.0.5 to 2024.0.6 #​16125
  • Bump org.springframework.ldap:spring-ldap-core from 3.2.7 to 3.2.8 #​16102
  • Bump org.springframework:spring-framework-bom from 6.1.14 to 6.1.15 #​16101

🔩 Build Updates

  • Bump @antora/collector-extension from 1.0.0-beta.4 to 1.0.0-beta.5 in /docs #​16117
  • Update Antora UI Spring to v0.4.17 #​15930

❤️ Contributors

Thank you to all the contributors who worked on this release:

@​asimuleo, @​dependabot[bot], @​github-actions[bot], and @​kse-music

v6.3.4

Compare Source

🪲 Bug Fixes

  • Annotation expression template processing should not fail on Class parameter types #​15711
  • Disabling credentials erasure on custom AuthenticationManager is not working #​15808
  • Documentation inconsistency in AuthorizationManager's verify method return type #​15822
  • Methods annotated with @PostFilter are processed twice by PostFilterAuthorizationMethodInterceptor #​15676
  • OidcBackChannelLogoutTokenValidator should not construct when missing OIDC Provider Issuer #​15868
  • SecurityJackson2Modules.getModules(): Cannot load module org.springframework.security.cas.jackson2.CasJackson2Module #​15767
  • The additionalParameters array parameter of OAuth2AuthorizationRequest causes the authorizationRequestUri to be incorrect #​15829

🔨 Dependency Upgrades

  • Bump ch.qos.logback:logback-classic from 1.5.10 to 1.5.11 #​15926
  • Bump io.micrometer:micrometer-observation from 1.12.10 to 1.12.11 #​15917
  • Bump io.mockk:mockk from 1.13.12 to 1.13.13 #​15897
  • Bump io.projectreactor:reactor-bom from 2023.0.10 to 2023.0.11 #​15925
  • Bump jakarta.servlet.jsp.jstl:jakarta.servlet.jsp.jstl-api from 3.0.1 to 3.0.2 #​15694
  • Bump org-eclipse-jetty from 11.0.23 to 11.0.24 #​15731
  • Bump org.jfrog.buildinfo:build-info-extractor-gradle from 4.33.21 to 4.33.22 #​15761
  • Bump org.junit:junit-bom from 5.10.4 to 5.10.5 #​15883
  • Bump org.springframework.data:spring-data-bom from 2024.0.4 to 2024.0.5 #​15958
  • Bump org.springframework.ldap:spring-ldap-core from 3.2.6 to 3.2.7 #​15944
  • Bump org.springframework:spring-framework-bom from 6.1.13 to 6.1.14 #​15945

🔩 Build Updates

  • Bump @antora/collector-extension from 1.0.0-beta.2 to 1.0.0-beta.3 in /docs #​15907
  • Bump @springio/asciidoctor-extensions from 1.0.0-alpha.13 to 1.0.0-alpha.14 in /docs #​15836
  • Migrate slack notifications to GChat #​15668
  • Release 6.3.4 #​15964
  • Update eclipse/vscode configuration to use -parameters #​15681

❤️ Contributors

Thank you to all the contributors who worked on this release:

@​dependabot[bot] and @​kse-music

v6.3.3

Compare Source

🪲 Bug Fixes
  • ObservationRegistry is never post-processed #​15658
🔨 Dependency Upgrades
  • Bump org-eclipse-jetty from 11.0.22 to 11.0.23 #​15664
❤️ Contributors

Thank you to all the contributors who worked on this release:

@​dependabot[bot]

v6.3.2

Compare Source

⭐ New Features
  • ActiveDirectoryLdapAuthenticationProvider does not implement support for multiple urls #​15495
  • Document the role of CredentialsContainer #​15321
  • OIDC Backchannel Logout should allow logout tokens having typ header of logout+jwt #​15410
🪲 Bug Fixes
  • A broken link in Spring Security reference #​15297
  • Documentation for ServletBearerExchangeFilterFunction incomplete or incorrect #​15460
  • EnableMethodSecurity should publish only one bean of each AuthorizationAdvisor #​15592
  • Fix Compromised Password Checker Docs Sample Not Working #​15305
  • Fix for #​15172 introduces significant performance degredation #​15324
  • Pre/PostAuthorize should not ignore HandleAuthorizationDenied#handlerClass when ApplicationContext is not provided #​15535
  • Update prerequisites documentation with Java 17 #​15340
  • Use Correct Meta-Annotation in Kotlin Sample #​15472
  • Using sec:authorize in JSPX causes 'java.lang.NullPointerException: Cannot invoke "jakarta.servlet.ServletRegistration.getClassName()" because "registration" is null' #​15440
🔨 Dependency Upgrades
  • Bump ch.qos.logback:logback-classic from 1.5.6 to 1.5.7 #​15619
  • Bump com.fasterxml.jackson:jackson-bom from 2.17.1 to 2.17.2 #​15374
  • Bump com.github.spullara.mustache.java:compiler from 0.9.13 to 0.9.14 #​15373
  • Bump io.micrometer:micrometer-observation from 1.12.7 to 1.12.8 #​15383
  • Bump io.micrometer:micrometer-observation from 1.12.8 to 1.12.9 #​15581
  • Bump io.mockk:mockk from 1.13.11 to 1.13.12 #​15430
  • Bump io.projectreactor:reactor-bom from 2023.0.7 to 2023.0.8 #​15388
  • Bump io.projectreactor:reactor-bom from 2023.0.8 to 2023.0.9 #​15597
  • Bump jakarta.servlet.jsp.jstl:jakarta.servlet.jsp.jstl-api from 3.0.0 to 3.0.1 #​15582
  • Bump org-apache-maven-resolver from 1.9.20 to 1.9.21 #​15372
  • Bump org-apache-maven-resolver from 1.9.21 to 1.9.22 #​15545
  • Bump org-eclipse-jetty from 11.0.21 to 11.0.22 #​15356
  • Bump org.apache.maven:maven-resolver-provider from 3.9.7 to 3.9.8 #​15268
  • Bump org.apache.maven:maven-resolver-provider from 3.9.8 to 3.9.9 #​15642
  • Bump org.gretty:gretty from 4.1.4 to 4.1.5 #​15431
  • Bump org.hibernate.orm:hibernate-core from 6.4.9.Final to 6.4.10.Final #​15530
  • Bump org.jetbrains.kotlin:kotlin-bom from 1.9.24 to 1.9.25 #​15456
  • Bump org.jetbrains.kotlin:kotlin-gradle-plugin from 1.9.24 to 1.9.25 #​15455
  • Bump org.jfrog.buildinfo:build-info-extractor-gradle from 4.33.19 to 4.33.20 #​15267
  • Bump org.junit:junit-bom from 5.10.2 to 5.10.3 #​15315
  • Bump org.skyscreamer:jsonassert from 1.5.1 to 1.5.3 #​15336
  • Bump org.slf4j:slf4j-api from 2.0.13 to 2.0.14 #​15529
  • Bump org.slf4j:slf4j-api from 2.0.14 to 2.0.15 #​15546
  • Bump org.slf4j:slf4j-api from 2.0.15 to 2.0.16 #​15571
  • Bump org.springframework.data:spring-data-bom from 2024.0.1 to 2024.0.2 #​15421
  • Bump org.springframework.data:spring-data-bom from 2024.0.2 to 2024.0.3 #​15643
  • Bump org.springframework.ldap:spring-ldap-core from 3.2.4 to 3.2.6 #​15620
  • Bump org.springframework:spring-framework-bom from 6.1.10 to 6.1.11 #​15402
  • Bump org.springframework:spring-framework-bom from 6.1.11 to 6.1.12 #​15613
  • Bump org.springframework:spring-framework-bom from 6.1.9 to 6.1.10 #​15279
🔩 Build Updates
  • Automate check of expected branch version #​15310
  • Bump @antora/collector-extension from 1.0.0-alpha.4 to 1.

Configuration

📅 Schedule: Branch creation - At any time (no schedule defined), Automerge - At any time (no schedule defined).

🚦 Automerge: Disabled by config. Please merge this manually once you are satisfied.

Rebasing: Whenever PR becomes conflicted, or you tick the rebase/retry checkbox.

🔕 Ignore: Close this PR and you won't be reminded about this update again.


  • If you want to rebase/retry this PR, check this box

This PR was generated by Mend Renovate. View the repository job log.

@renovate renovate bot force-pushed the renovate/spring-security branch from 265c4a7 to 0de641c Compare May 20, 2024 19:20
@renovate renovate bot changed the title fix(deps): update dependency org.springframework.security:spring-security-test to v6.2.4 fix(deps): update dependency org.springframework.security:spring-security-test to v6.3.0 May 20, 2024
@renovate renovate bot force-pushed the renovate/spring-security branch from 0de641c to 2359c42 Compare June 17, 2024 18:41
@renovate renovate bot changed the title fix(deps): update dependency org.springframework.security:spring-security-test to v6.3.0 fix(deps): update dependency org.springframework.security:spring-security-test to v6.3.1 Jun 17, 2024
@renovate renovate bot force-pushed the renovate/spring-security branch from 2359c42 to b34f154 Compare August 19, 2024 22:19
@renovate renovate bot changed the title fix(deps): update dependency org.springframework.security:spring-security-test to v6.3.1 fix(deps): update dependency org.springframework.security:spring-security-test to v6.3.2 Aug 19, 2024
@renovate renovate bot force-pushed the renovate/spring-security branch from b34f154 to 18acf61 Compare August 21, 2024 17:50
@renovate renovate bot changed the title fix(deps): update dependency org.springframework.security:spring-security-test to v6.3.2 fix(deps): update dependency org.springframework.security:spring-security-test to v6.3.3 Aug 21, 2024
@renovate renovate bot force-pushed the renovate/spring-security branch from 18acf61 to 945fca0 Compare October 21, 2024 19:26
@renovate renovate bot changed the title fix(deps): update dependency org.springframework.security:spring-security-test to v6.3.3 fix(deps): update dependency org.springframework.security:spring-security-test to v6.3.4 Oct 21, 2024
@renovate renovate bot force-pushed the renovate/spring-security branch from 945fca0 to 5bef347 Compare November 19, 2024 13:52
@renovate renovate bot changed the title fix(deps): update dependency org.springframework.security:spring-security-test to v6.3.4 fix(deps): update dependency org.springframework.security:spring-security-test to v6.4.0 Nov 19, 2024
@renovate renovate bot force-pushed the renovate/spring-security branch from 5bef347 to a3f7584 Compare November 21, 2024 14:58
@renovate renovate bot changed the title fix(deps): update dependency org.springframework.security:spring-security-test to v6.4.0 fix(deps): update dependency org.springframework.security:spring-security-test to v6.4.1 Nov 21, 2024
@renovate renovate bot force-pushed the renovate/spring-security branch from a3f7584 to 7225761 Compare December 16, 2024 20:09
@renovate renovate bot changed the title fix(deps): update dependency org.springframework.security:spring-security-test to v6.4.1 fix(deps): update dependency org.springframework.security:spring-security-test to v6.4.2 Dec 16, 2024
@renovate renovate bot force-pushed the renovate/spring-security branch from 7225761 to 2b53cf9 Compare February 18, 2025 18:57
@renovate renovate bot changed the title fix(deps): update dependency org.springframework.security:spring-security-test to v6.4.2 fix(deps): update dependency org.springframework.security:spring-security-test to v6.4.3 Feb 18, 2025
@renovate renovate bot force-pushed the renovate/spring-security branch from 2b53cf9 to 334252b Compare March 17, 2025 23:23
@renovate renovate bot changed the title fix(deps): update dependency org.springframework.security:spring-security-test to v6.4.3 fix(deps): update dependency org.springframework.security:spring-security-test to v6.4.4 Mar 17, 2025
@renovate renovate bot force-pushed the renovate/spring-security branch from 334252b to 4e3457c Compare April 21, 2025 17:28
@renovate renovate bot changed the title fix(deps): update dependency org.springframework.security:spring-security-test to v6.4.4 fix(deps): update dependency org.springframework.security:spring-security-test to v6.4.5 Apr 21, 2025
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
Projects
None yet
Development

Successfully merging this pull request may close these issues.

0 participants