Josh Cummings
7a37172964
Fix Formatting and Style
...
Signed-off-by: Josh Cummings <3627351+jzheaux@users.noreply.github.com >
2026-09-04 11:53:48 -06:00
Josh Cummings
fe125a4088
Merge branch '7.0.x' into dependabot/gradle/7.1.x/io-spring-javaformat-0.0.48
...
# Conflicts:
# core/src/main/java/org/springframework/security/access/expression/SecurityExpressionRoot.java
# ldap/src/main/java/org/springframework/security/ldap/authentication/AbstractLdapAuthenticator.java
# ldap/src/main/java/org/springframework/security/ldap/ppolicy/PasswordPolicyResponseControl.java
# oauth2/oauth2-core/src/main/java/org/springframework/security/oauth2/core/OAuth2TokenIntrospectionClaimAccessor.java
# oauth2/oauth2-resource-server/src/main/java/org/springframework/security/oauth2/server/resource/authentication/JwtAuthenticationToken.java
# oauth2/oauth2-resource-server/src/main/java/org/springframework/security/oauth2/server/resource/introspection/SpringOpaqueTokenIntrospector.java
# oauth2/oauth2-resource-server/src/main/java/org/springframework/security/oauth2/server/resource/introspection/SpringReactiveOpaqueTokenIntrospector.java
# oauth2/oauth2-resource-server/src/main/java/org/springframework/security/oauth2/server/resource/web/BearerTokenAuthenticationEntryPoint.java
# saml2/saml2-service-provider/src/main/java/org/springframework/security/saml2/jackson/DefaultSaml2AuthenticatedPrincipalMixin.java
# saml2/saml2-service-provider/src/main/java/org/springframework/security/saml2/jackson/Saml2AssertionAuthenticationMixin.java
# saml2/saml2-service-provider/src/main/java/org/springframework/security/saml2/jackson/Saml2AuthenticationExceptionMixin.java
# saml2/saml2-service-provider/src/main/java/org/springframework/security/saml2/jackson/Saml2AuthenticationMixin.java
# saml2/saml2-service-provider/src/main/java/org/springframework/security/saml2/jackson/Saml2ErrorMixin.java
# saml2/saml2-service-provider/src/main/java/org/springframework/security/saml2/jackson/Saml2LogoutRequestMixin.java
# saml2/saml2-service-provider/src/main/java/org/springframework/security/saml2/jackson/Saml2PostAuthenticationRequestMixin.java
# saml2/saml2-service-provider/src/main/java/org/springframework/security/saml2/jackson/Saml2RedirectAuthenticationRequestMixin.java
# saml2/saml2-service-provider/src/main/java/org/springframework/security/saml2/jackson/SimpleSaml2ResponseAssertionAccessorMixin.java
# saml2/saml2-service-provider/src/main/java/org/springframework/security/saml2/jackson2/DefaultSaml2AuthenticatedPrincipalMixin.java
# saml2/saml2-service-provider/src/main/java/org/springframework/security/saml2/jackson2/Saml2AssertionAuthenticationMixin.java
# saml2/saml2-service-provider/src/main/java/org/springframework/security/saml2/jackson2/Saml2AuthenticationExceptionMixin.java
# saml2/saml2-service-provider/src/main/java/org/springframework/security/saml2/jackson2/Saml2AuthenticationMixin.java
# saml2/saml2-service-provider/src/main/java/org/springframework/security/saml2/jackson2/Saml2ErrorMixin.java
# saml2/saml2-service-provider/src/main/java/org/springframework/security/saml2/jackson2/Saml2LogoutRequestMixin.java
# saml2/saml2-service-provider/src/main/java/org/springframework/security/saml2/jackson2/Saml2PostAuthenticationRequestMixin.java
# saml2/saml2-service-provider/src/main/java/org/springframework/security/saml2/jackson2/Saml2RedirectAuthenticationRequestMixin.java
# saml2/saml2-service-provider/src/main/java/org/springframework/security/saml2/jackson2/SimpleSaml2ResponseAssertionAccessorMixin.java
# web/src/main/java/org/springframework/security/web/jackson/DefaultSavedRequestMixin.java
2026-09-04 10:42:43 -06:00
dependabot[bot]
a37c0ac9ce
Bump io-spring-javaformat from 0.0.47 to 0.0.48
...
Bumps `io-spring-javaformat` from 0.0.47 to 0.0.48.
Updates `io.spring.javaformat:spring-javaformat-checkstyle` from 0.0.47 to 0.0.48
- [Release notes](https://github.com/spring-io/spring-javaformat/releases )
- [Commits](https://github.com/spring-io/spring-javaformat/compare/v0.0.47...v0.0.48 )
Updates `io.spring.javaformat:spring-javaformat-gradle-plugin` from 0.0.47 to 0.0.48
- [Release notes](https://github.com/spring-io/spring-javaformat/releases )
- [Commits](https://github.com/spring-io/spring-javaformat/compare/v0.0.47...v0.0.48 )
---
updated-dependencies:
- dependency-name: io.spring.javaformat:spring-javaformat-checkstyle
dependency-version: 0.0.48
dependency-type: direct:production
update-type: version-update:semver-patch
- dependency-name: io.spring.javaformat:spring-javaformat-gradle-plugin
dependency-version: 0.0.48
dependency-type: direct:production
update-type: version-update:semver-patch
...
Signed-off-by: dependabot[bot] <support@github.com >
2026-09-04 10:26:18 -06:00
Josh Cummings
a551be65eb
Update Formatting and Style
...
Signed-off-by: Josh Cummings <3627351+jzheaux@users.noreply.github.com >
2026-09-04 09:24:19 -07:00
dependabot[bot]
5449cca3e7
Bump io-spring-javaformat from 0.0.47 to 0.0.48
...
Bumps `io-spring-javaformat` from 0.0.47 to 0.0.48.
Updates `io.spring.javaformat:spring-javaformat-checkstyle` from 0.0.47 to 0.0.48
- [Release notes](https://github.com/spring-io/spring-javaformat/releases )
- [Commits](https://github.com/spring-io/spring-javaformat/compare/v0.0.47...v0.0.48 )
Updates `io.spring.javaformat:spring-javaformat-gradle-plugin` from 0.0.47 to 0.0.48
- [Release notes](https://github.com/spring-io/spring-javaformat/releases )
- [Commits](https://github.com/spring-io/spring-javaformat/compare/v0.0.47...v0.0.48 )
---
updated-dependencies:
- dependency-name: io.spring.javaformat:spring-javaformat-checkstyle
dependency-version: 0.0.48
dependency-type: direct:production
update-type: version-update:semver-patch
- dependency-name: io.spring.javaformat:spring-javaformat-gradle-plugin
dependency-version: 0.0.48
dependency-type: direct:production
update-type: version-update:semver-patch
...
Signed-off-by: dependabot[bot] <support@github.com >
2026-09-04 09:24:19 -07:00
Josh Cummings
01891c8032
Merge branch '7.0.x' into 7.1.x
2026-09-04 09:02:29 -06:00
dependabot[bot]
671cb75c72
Bump antora from 3.2.0-rc.3 to 3.2.0 in /docs
...
Bumps [antora](https://gitlab.com/antora/antora/tree/HEAD/packages/antora ) from 3.2.0-rc.3 to 3.2.0.
- [Changelog](https://gitlab.com/antora/antora/blob/main/CHANGELOG.adoc )
- [Commits](https://gitlab.com/antora/antora/compare/v3.2.0-rc.3...v3.2.0 )
---
updated-dependencies:
- dependency-name: antora
dependency-version: 3.2.0
dependency-type: direct:production
update-type: version-update:semver-patch
...
Signed-off-by: dependabot[bot] <support@github.com >
2026-09-04 08:02:13 -07:00
Josh Cummings
201adb3101
Merge branch '7.0.x' into 7.1.x
2026-09-04 08:59:03 -06:00
Josh Cummings
81ce86800e
Update to spring-release-actions 0.0.6
...
Signed-off-by: Josh Cummings <3627351+jzheaux@users.noreply.github.com >
2026-09-04 08:58:54 -06:00
Josh Cummings
312e0a4529
Merge branch '7.0.x' into 7.1.x
2026-09-04 08:52:35 -06:00
Josh Cummings
d5ac3a86bc
Update Workflows to spring-security-release-tools 1.0.17
...
Signed-off-by: Josh Cummings <3627351+jzheaux@users.noreply.github.com >
2026-09-04 08:50:46 -06:00
dependabot[bot]
9ad6b51aec
Bump spring-io/spring-security-release-tools/.github/workflows/release-announcements-publish.yml
...
Bumps [spring-io/spring-security-release-tools/.github/workflows/release-announcements-publish.yml](https://github.com/spring-io/spring-security-release-tools ) from 1.0.16 to 1.0.17.
- [Release notes](https://github.com/spring-io/spring-security-release-tools/releases )
- [Changelog](https://github.com/spring-io/spring-security-release-tools/blob/main/RELEASE.adoc )
- [Commits](https://github.com/spring-io/spring-security-release-tools/compare/d6c65d3013c0888e2c9cbae9f4beda610994776c...3f6cc7ffc137ca160061749d5f34dc30d5f36986 )
---
updated-dependencies:
- dependency-name: spring-io/spring-security-release-tools/.github/workflows/release-announcements-publish.yml
dependency-version: 1.0.17
dependency-type: direct:production
update-type: version-update:semver-patch
...
Signed-off-by: dependabot[bot] <support@github.com >
2026-09-04 07:30:49 -07:00
dependabot[bot]
a501e214f4
Bump spring-io/spring-security-release-tools/.github/actions/send-notification
...
Bumps [spring-io/spring-security-release-tools/.github/actions/send-notification](https://github.com/spring-io/spring-security-release-tools ) from 1.0.15 to 1.0.17.
- [Release notes](https://github.com/spring-io/spring-security-release-tools/releases )
- [Changelog](https://github.com/spring-io/spring-security-release-tools/blob/main/RELEASE.adoc )
- [Commits](https://github.com/spring-io/spring-security-release-tools/compare/b92832ecbc7cbe969201e6beafbde0ee400cf095...3f6cc7ffc137ca160061749d5f34dc30d5f36986 )
---
updated-dependencies:
- dependency-name: spring-io/spring-security-release-tools/.github/actions/send-notification
dependency-version: 1.0.17
dependency-type: direct:production
update-type: version-update:semver-patch
...
Signed-off-by: dependabot[bot] <support@github.com >
2026-09-04 07:30:24 -07:00
dependabot[bot]
e05cec1b7d
Bump spring-io/spring-release-actions/schedule-milestone
...
Bumps [spring-io/spring-release-actions/schedule-milestone](https://github.com/spring-io/spring-release-actions ) from 0.0.5 to 0.0.6.
- [Release notes](https://github.com/spring-io/spring-release-actions/releases )
- [Commits](https://github.com/spring-io/spring-release-actions/compare/a1f321783a0769dd2aea4fad6c2ae2f95a52b885...1b8671612c3eb3d9b9763e2d7b66f1a80d00ee95 )
---
updated-dependencies:
- dependency-name: spring-io/spring-release-actions/schedule-milestone
dependency-version: 0.0.6
dependency-type: direct:production
update-type: version-update:semver-patch
...
Signed-off-by: dependabot[bot] <support@github.com >
2026-09-04 07:30:03 -07:00
dependabot[bot]
b39e300395
Bump spring-io/spring-release-actions/compute-version
...
Bumps [spring-io/spring-release-actions/compute-version](https://github.com/spring-io/spring-release-actions ) from 0.0.5 to 0.0.6.
- [Release notes](https://github.com/spring-io/spring-release-actions/releases )
- [Commits](https://github.com/spring-io/spring-release-actions/compare/a1f321783a0769dd2aea4fad6c2ae2f95a52b885...1b8671612c3eb3d9b9763e2d7b66f1a80d00ee95 )
---
updated-dependencies:
- dependency-name: spring-io/spring-release-actions/compute-version
dependency-version: 0.0.6
dependency-type: direct:production
update-type: version-update:semver-patch
...
Signed-off-by: dependabot[bot] <support@github.com >
2026-09-04 07:29:12 -07:00
dependabot[bot]
7ea44bbb26
Bump antora from 3.2.0-rc.3 to 3.2.0 in /docs
...
Bumps [antora](https://gitlab.com/antora/antora/tree/HEAD/packages/antora ) from 3.2.0-rc.3 to 3.2.0.
- [Changelog](https://gitlab.com/antora/antora/blob/main/CHANGELOG.adoc )
- [Commits](https://gitlab.com/antora/antora/compare/v3.2.0-rc.3...v3.2.0 )
---
updated-dependencies:
- dependency-name: antora
dependency-version: 3.2.0
dependency-type: direct:production
update-type: version-update:semver-patch
...
Signed-off-by: dependabot[bot] <support@github.com >
2026-09-04 07:28:40 -07:00
dependabot[bot]
8130568ac6
Bump spring-io/spring-security-release-tools/.github/workflows/deploy-artifacts.yml
...
Bumps [spring-io/spring-security-release-tools/.github/workflows/deploy-artifacts.yml](https://github.com/spring-io/spring-security-release-tools ) from 1.0.15 to 1.0.17.
- [Release notes](https://github.com/spring-io/spring-security-release-tools/releases )
- [Changelog](https://github.com/spring-io/spring-security-release-tools/blob/main/RELEASE.adoc )
- [Commits](https://github.com/spring-io/spring-security-release-tools/compare/b92832ecbc7cbe969201e6beafbde0ee400cf095...3f6cc7ffc137ca160061749d5f34dc30d5f36986 )
---
updated-dependencies:
- dependency-name: spring-io/spring-security-release-tools/.github/workflows/deploy-artifacts.yml
dependency-version: 1.0.17
dependency-type: direct:production
update-type: version-update:semver-patch
...
Signed-off-by: dependabot[bot] <support@github.com >
2026-09-04 07:25:08 -07:00
dependabot[bot]
a4707d9e19
Bump org.hibernate.orm:hibernate-core from 7.4.6.Final to 7.4.7.Final
...
Bumps [org.hibernate.orm:hibernate-core](https://github.com/hibernate/hibernate-orm ) from 7.4.6.Final to 7.4.7.Final.
- [Release notes](https://github.com/hibernate/hibernate-orm/releases )
- [Changelog](https://github.com/hibernate/hibernate-orm/blob/7.4.7/changelog.txt )
- [Commits](https://github.com/hibernate/hibernate-orm/compare/7.4.6...7.4.7 )
---
updated-dependencies:
- dependency-name: org.hibernate.orm:hibernate-core
dependency-version: 7.4.7.Final
dependency-type: direct:production
update-type: version-update:semver-patch
...
Signed-off-by: dependabot[bot] <support@github.com >
2026-09-04 07:23:29 -07:00
dependabot[bot]
137d2e81b7
Bump io.spring.nullability:io.spring.nullability.gradle.plugin
...
Bumps [io.spring.nullability:io.spring.nullability.gradle.plugin](https://github.com/spring-gradle-plugins/nullability-plugin ) from 0.0.14 to 0.0.15.
- [Release notes](https://github.com/spring-gradle-plugins/nullability-plugin/releases )
- [Commits](https://github.com/spring-gradle-plugins/nullability-plugin/compare/v0.0.14...v0.0.15 )
---
updated-dependencies:
- dependency-name: io.spring.nullability:io.spring.nullability.gradle.plugin
dependency-version: 0.0.15
dependency-type: direct:production
update-type: version-update:semver-patch
...
Signed-off-by: dependabot[bot] <support@github.com >
2026-09-04 00:30:20 +00:00
Josh Cummings
8525cbfd19
Fix Nullability
...
Signed-off-by: Josh Cummings <3627351+jzheaux@users.noreply.github.com >
2026-09-04 00:30:20 +00:00
Josh Cummings
02f5f5a459
Merge branch '7.0.x' into 7.1.x
2026-09-03 15:42:29 -06:00
dependabot[bot]
3dff446d18
Bump spring-io/spring-release-actions/get-todays-release-version
...
Bumps [spring-io/spring-release-actions/get-todays-release-version](https://github.com/spring-io/spring-release-actions ) from 0.0.5 to 0.0.6.
- [Release notes](https://github.com/spring-io/spring-release-actions/releases )
- [Commits](https://github.com/spring-io/spring-release-actions/compare/a1f321783a0769dd2aea4fad6c2ae2f95a52b885...1b8671612c3eb3d9b9763e2d7b66f1a80d00ee95 )
---
updated-dependencies:
- dependency-name: spring-io/spring-release-actions/get-todays-release-version
dependency-version: 0.0.6
dependency-type: direct:production
update-type: version-update:semver-patch
...
Signed-off-by: dependabot[bot] <support@github.com >
2026-09-03 14:39:30 -07:00
dependabot[bot]
cc89707b03
Bump antora from 3.2.0-rc.2 to 3.2.0-rc.3 in /docs
...
Bumps [antora](https://gitlab.com/antora/antora ) from 3.2.0-rc.2 to 3.2.0-rc.3.
- [Changelog](https://gitlab.com/antora/antora/blob/main/CHANGELOG.adoc )
- [Commits](https://gitlab.com/antora/antora/compare/v3.2.0-rc.2...v3.2.0-rc.3 )
---
updated-dependencies:
- dependency-name: antora
dependency-version: 3.2.0-rc.3
dependency-type: direct:production
update-type: version-update:semver-patch
...
Signed-off-by: dependabot[bot] <support@github.com >
2026-09-03 14:38:41 -07:00
dependabot[bot]
812ad9c547
Bump spring-io/spring-security-release-tools/.github/workflows/build.yml
...
Bumps [spring-io/spring-security-release-tools/.github/workflows/build.yml](https://github.com/spring-io/spring-security-release-tools ) from 1.0.15 to 1.0.17.
- [Release notes](https://github.com/spring-io/spring-security-release-tools/releases )
- [Changelog](https://github.com/spring-io/spring-security-release-tools/blob/main/RELEASE.adoc )
- [Commits](https://github.com/spring-io/spring-security-release-tools/compare/b92832ecbc7cbe969201e6beafbde0ee400cf095...3f6cc7ffc137ca160061749d5f34dc30d5f36986 )
---
updated-dependencies:
- dependency-name: spring-io/spring-security-release-tools/.github/workflows/build.yml
dependency-version: 1.0.17
dependency-type: direct:production
update-type: version-update:semver-patch
...
Signed-off-by: dependabot[bot] <support@github.com >
2026-09-03 14:38:08 -07:00
dependabot[bot]
364c153e17
Bump spring-io/spring-release-actions/compute-next-version
...
Bumps [spring-io/spring-release-actions/compute-next-version](https://github.com/spring-io/spring-release-actions ) from 0.0.5 to 0.0.6.
- [Release notes](https://github.com/spring-io/spring-release-actions/releases )
- [Commits](https://github.com/spring-io/spring-release-actions/compare/a1f321783a0769dd2aea4fad6c2ae2f95a52b885...1b8671612c3eb3d9b9763e2d7b66f1a80d00ee95 )
---
updated-dependencies:
- dependency-name: spring-io/spring-release-actions/compute-next-version
dependency-version: 0.0.6
dependency-type: direct:production
update-type: version-update:semver-patch
...
Signed-off-by: dependabot[bot] <support@github.com >
2026-09-03 14:37:16 -07:00
dependabot[bot]
39383ab970
Bump spring-io/spring-security-release-tools/.github/workflows/test.yml
...
Bumps [spring-io/spring-security-release-tools/.github/workflows/test.yml](https://github.com/spring-io/spring-security-release-tools ) from ed473b4dafba053c63a453d2d88a89df3b3e18b3 to 9ca0acea761aa79d71c78cc462048c49ed5c4230.
- [Release notes](https://github.com/spring-io/spring-security-release-tools/releases )
- [Changelog](https://github.com/spring-io/spring-security-release-tools/blob/main/RELEASE.adoc )
- [Commits](https://github.com/spring-io/spring-security-release-tools/compare/ed473b4dafba053c63a453d2d88a89df3b3e18b3...9ca0acea761aa79d71c78cc462048c49ed5c4230 )
---
updated-dependencies:
- dependency-name: spring-io/spring-security-release-tools/.github/workflows/test.yml
dependency-version: 9ca0acea761aa79d71c78cc462048c49ed5c4230
dependency-type: direct:production
...
Signed-off-by: dependabot[bot] <support@github.com >
2026-09-03 14:35:20 -07:00
Tran Ngoc Nhan
8ef5bcd003
Fix typos in Javadocs
...
- Remove duplicate words
- Remove unnecessary parentheses
- Fix grammar
Signed-off-by: Tran Ngoc Nhan <ngocnhan.tran1996@gmail.com >
2026-09-03 14:34:29 -07:00
dependabot[bot]
4193b73d47
Bump actions/setup-java from 5.7.0 to 6.0.0
...
Bumps [actions/setup-java](https://github.com/actions/setup-java ) from 5.7.0 to 6.0.0.
- [Release notes](https://github.com/actions/setup-java/releases )
- [Commits](https://github.com/actions/setup-java/compare/b6effb05e454b25005698d916606bdc6ffcbf961...dd06d9cba3e5552c54d9f8ea23572deb30010f7c )
---
updated-dependencies:
- dependency-name: actions/setup-java
dependency-version: 6.0.0
dependency-type: direct:production
update-type: version-update:semver-major
...
Signed-off-by: dependabot[bot] <support@github.com >
2026-09-03 14:33:13 -07:00
dependabot[bot]
4ce48297f6
Bump io.spring.gradle:spring-security-release-plugin
...
Bumps [io.spring.gradle:spring-security-release-plugin](https://github.com/spring-io/spring-security-release-tools ) from 1.0.15 to 1.0.17.
- [Release notes](https://github.com/spring-io/spring-security-release-tools/releases )
- [Changelog](https://github.com/spring-io/spring-security-release-tools/blob/main/RELEASE.adoc )
- [Commits](https://github.com/spring-io/spring-security-release-tools/compare/v1.0.15...v1.0.17 )
---
updated-dependencies:
- dependency-name: io.spring.gradle:spring-security-release-plugin
dependency-version: 1.0.17
dependency-type: direct:production
update-type: version-update:semver-patch
...
Signed-off-by: dependabot[bot] <support@github.com >
2026-09-03 14:32:07 -07:00
Josh Cummings
9989735a49
Merge branch '7.0.x' into 7.1.x
...
Closes gh-19648
2026-09-03 15:22:26 -06:00
Tran Ngoc Nhan
02cc2e9d14
Fix TokenType Comparison Logic
...
Compare OAuth2AccessToken.TokenType using equals() instead of == in
BearerTokenAuthentication, since TokenType instances are not
guaranteed to be singletons and reference comparison can incorrectly
reject an otherwise-equal bearer token.
Closes gh-19377
Signed-off-by: Josh Cummings <3627351+jzheaux@users.noreply.github.com >
2026-09-03 14:06:08 -07:00
Josh Cummings
118e51d45e
Merge branch '7.0.x' into 7.1.x
2026-09-03 15:01:11 -06:00
Tran Ngoc Nhan
27a76a67ae
Include code example for reactive onetimetoken
...
Signed-off-by: Tran Ngoc Nhan <ngocnhan.tran1996@gmail.com >
2026-09-03 14:00:44 -07:00
Tran Ngoc Nhan
ff6cef0cd2
Include code example for servlet onetimetoken
...
Signed-off-by: Tran Ngoc Nhan <ngocnhan.tran1996@gmail.com >
2026-09-03 14:00:44 -07:00
Josh Cummings
801f890ed0
Merge branch '7.0.x' into 7.1.x
...
Closes gh-9175 on 7.1.x
2026-09-03 12:26:14 -06:00
Josh Cummings
1a7769be28
Fix Checkstyle
...
Issue gh-9175
Signed-off-by: Josh Cummings <3627351+jzheaux@users.noreply.github.com >
2026-09-03 11:18:58 -07:00
Dmitrii Bocharov
bdf501fe87
Fix HeaderWriterFilter Race Condition
...
Closes gh-9175
Signed-off-by: Dmitrii Bocharov <bdshadow@gmail.com >
2026-09-03 11:18:58 -07:00
Josh Cummings
a161421409
Turn Off Auto-merge for Maintenance Branch
...
This commit removes the auto-merge workflow on 7.1.x since it
is a maintenance branch.
Closes gh-19631
Signed-off-by: Josh Cummings <3627351+jzheaux@users.noreply.github.com >
2026-08-31 10:41:54 -06:00
Joe Grandja
978eb4396a
Polish gh-19585
2026-08-31 11:09:18 -04:00
Evgeniy Cheban
770c860d9d
Ensure WebSession ID is not changed after token refresh (Reactive)
...
Closes gh-19424
Signed-off-by: Evgeniy Cheban <mister.cheban@gmail.com >
2026-08-31 10:11:13 -04:00
dependabot[bot]
11890f2f49
Bump io.spring.gradle:spring-security-release-plugin
...
Bumps [io.spring.gradle:spring-security-release-plugin](https://github.com/spring-io/spring-security-release-tools ) from 1.0.16 to 1.0.17.
- [Release notes](https://github.com/spring-io/spring-security-release-tools/releases )
- [Changelog](https://github.com/spring-io/spring-security-release-tools/blob/main/RELEASE.adoc )
- [Commits](https://github.com/spring-io/spring-security-release-tools/compare/v1.0.16...v1.0.17 )
---
updated-dependencies:
- dependency-name: io.spring.gradle:spring-security-release-plugin
dependency-version: 1.0.17
dependency-type: direct:production
update-type: version-update:semver-patch
...
Signed-off-by: dependabot[bot] <support@github.com >
2026-08-28 03:17:31 +00:00
dependabot[bot]
5809451de7
Bump spring-io/spring-release-actions/compute-next-version
...
Bumps [spring-io/spring-release-actions/compute-next-version](https://github.com/spring-io/spring-release-actions ) from 0.0.5 to 0.0.6.
- [Release notes](https://github.com/spring-io/spring-release-actions/releases )
- [Commits](https://github.com/spring-io/spring-release-actions/compare/a1f321783a0769dd2aea4fad6c2ae2f95a52b885...1b8671612c3eb3d9b9763e2d7b66f1a80d00ee95 )
---
updated-dependencies:
- dependency-name: spring-io/spring-release-actions/compute-next-version
dependency-version: 0.0.6
dependency-type: direct:production
update-type: version-update:semver-patch
...
Signed-off-by: dependabot[bot] <support@github.com >
2026-08-28 00:50:20 +00:00
dependabot[bot]
31d379a7bf
Bump spring-io/spring-security-release-tools/.github/workflows/release-announcements-stage.yml
...
Bumps [spring-io/spring-security-release-tools/.github/workflows/release-announcements-stage.yml](https://github.com/spring-io/spring-security-release-tools ) from 1.0.16 to 1.0.17.
- [Release notes](https://github.com/spring-io/spring-security-release-tools/releases )
- [Changelog](https://github.com/spring-io/spring-security-release-tools/blob/main/RELEASE.adoc )
- [Commits](https://github.com/spring-io/spring-security-release-tools/compare/d6c65d3013c0888e2c9cbae9f4beda610994776c...3f6cc7ffc137ca160061749d5f34dc30d5f36986 )
---
updated-dependencies:
- dependency-name: spring-io/spring-security-release-tools/.github/workflows/release-announcements-stage.yml
dependency-version: 1.0.17
dependency-type: direct:production
update-type: version-update:semver-patch
...
Signed-off-by: dependabot[bot] <support@github.com >
2026-08-28 00:47:19 +00:00
dependabot[bot]
825370f8e3
Bump spring-io/spring-security-release-tools/.github/workflows/deploy-schema.yml
...
Bumps [spring-io/spring-security-release-tools/.github/workflows/deploy-schema.yml](https://github.com/spring-io/spring-security-release-tools ) from 1.0.15 to 1.0.17.
- [Release notes](https://github.com/spring-io/spring-security-release-tools/releases )
- [Changelog](https://github.com/spring-io/spring-security-release-tools/blob/main/RELEASE.adoc )
- [Commits](https://github.com/spring-io/spring-security-release-tools/compare/v1.0.15...3f6cc7ffc137ca160061749d5f34dc30d5f36986 )
---
updated-dependencies:
- dependency-name: spring-io/spring-security-release-tools/.github/workflows/deploy-schema.yml
dependency-version: 1.0.17
dependency-type: direct:production
update-type: version-update:semver-patch
...
Signed-off-by: dependabot[bot] <support@github.com >
2026-08-28 00:47:16 +00:00
Josh Cummings
edaae1d17d
Merge branch '7.0.x' into 7.1.x
2026-08-26 10:17:34 -06:00
dependabot[bot]
e8084090ff
Bump org.hibernate.orm:hibernate-core from 7.4.5.Final to 7.4.6.Final
...
Bumps [org.hibernate.orm:hibernate-core](https://github.com/hibernate/hibernate-orm ) from 7.4.5.Final to 7.4.6.Final.
- [Release notes](https://github.com/hibernate/hibernate-orm/releases )
- [Changelog](https://github.com/hibernate/hibernate-orm/blob/7.4.6/changelog.txt )
- [Commits](https://github.com/hibernate/hibernate-orm/compare/7.4.5...7.4.6 )
---
updated-dependencies:
- dependency-name: org.hibernate.orm:hibernate-core
dependency-version: 7.4.6.Final
dependency-type: direct:production
update-type: version-update:semver-patch
...
Signed-off-by: dependabot[bot] <support@github.com >
2026-08-26 03:24:42 +00:00
dependabot[bot]
4773b40f02
Bump gradle-wrapper from 9.7.0 to 9.7.1
...
Bumps [gradle-wrapper](https://github.com/gradle/gradle ) from 9.7.0 to 9.7.1.
- [Release notes](https://github.com/gradle/gradle/releases )
- [Commits](https://github.com/gradle/gradle/compare/v9.7.0...v9.7.1 )
---
updated-dependencies:
- dependency-name: gradle-wrapper
dependency-version: 9.7.1
dependency-type: direct:production
update-type: version-update:semver-patch
...
Signed-off-by: dependabot[bot] <support@github.com >
2026-08-24 03:28:40 +00:00
dependabot[bot]
9a4a965b0d
Bump io.spring.gradle:spring-security-release-plugin
...
Bumps [io.spring.gradle:spring-security-release-plugin](https://github.com/spring-io/spring-security-release-tools ) from 1.0.15 to 1.0.16.
- [Release notes](https://github.com/spring-io/spring-security-release-tools/releases )
- [Changelog](https://github.com/spring-io/spring-security-release-tools/blob/main/RELEASE.adoc )
- [Commits](https://github.com/spring-io/spring-security-release-tools/compare/v1.0.15...v1.0.16 )
---
updated-dependencies:
- dependency-name: io.spring.gradle:spring-security-release-plugin
dependency-version: 1.0.16
dependency-type: direct:production
update-type: version-update:semver-patch
...
Signed-off-by: dependabot[bot] <support@github.com >
2026-08-24 03:27:38 +00:00
Josh Cummings
0bae8a73d1
Next Development Version
...
Signed-off-by: Josh Cummings <3627351+jzheaux@users.noreply.github.com >
2026-08-21 09:14:37 -06:00
Josh Cummings
461ccd817d
Next Development Version
...
Signed-off-by: Josh Cummings <3627351+jzheaux@users.noreply.github.com >
2026-08-21 09:14:09 -06:00
Josh Cummings
8dc341af8c
Merge branch '7.0.x' into 7.1.x
...
Closes gh-19572
2026-08-20 16:58:02 -06:00
Josh Cummings
381c556f78
Add Release Announcement Workflows
...
Closes gh-19571
Signed-off-by: Josh Cummings <3627351+jzheaux@users.noreply.github.com >
2026-08-20 16:57:48 -06:00
Josh Cummings
6b2f892e66
Merge branch '7.0.x' into 7.1.x
...
Closes gh-19567
# Conflicts:
# config/src/main/java/org/springframework/security/config/annotation/web/configurers/oauth2/server/resource/DPoPAuthenticationConfigurer.java
# config/src/main/java/org/springframework/security/config/annotation/web/configurers/oauth2/server/resource/OAuth2ResourceServerConfigurer.java
# config/src/test/java/org/springframework/security/config/annotation/web/configurers/oauth2/server/resource/DPoPAuthenticationTests.java
# gradle/libs.versions.toml
# oauth2/oauth2-authorization-server/src/main/java/org/springframework/security/oauth2/server/authorization/InMemoryOAuth2AuthorizationService.java
# oauth2/oauth2-jose/src/main/java/org/springframework/security/oauth2/jwt/DPoPProofJwtDecoderFactory.java
# oauth2/oauth2-jose/src/main/java/org/springframework/security/oauth2/jwt/DPoPProofReplayValidator.java
# oauth2/oauth2-resource-server/src/main/java/org/springframework/security/oauth2/server/resource/authentication/DPoPAuthenticationProvider.java
2026-08-20 12:23:20 -06:00
Josh Cummings
3b276e6c0d
Update to Spring Data 2025.1.7
...
Closes gh-19485
Signed-off-by: Josh Cummings <3627351+jzheaux@users.noreply.github.com >
2026-08-20 11:24:08 -06:00
Josh Cummings
f2115fbef8
Update to Spring LDAP 4.0.5
...
Closes gh-19486
Signed-off-by: Josh Cummings <3627351+jzheaux@users.noreply.github.com >
2026-08-20 11:24:01 -06:00
Josh Cummings
298335a57e
Update to Micrometer 1.16.7
...
Closes gh-19484
Signed-off-by: Josh Cummings <3627351+jzheaux@users.noreply.github.com >
2026-08-20 11:23:55 -06:00
Josh Cummings
c6566ee772
Update to Reactor 2025.0.7
...
Closes gh-19483
Signed-off-by: Josh Cummings <3627351+jzheaux@users.noreply.github.com >
2026-08-20 11:23:50 -06:00
Josh Cummings
7442214225
Update to Spring Framework 7.0.9
...
Closes gh-19482
Signed-off-by: Josh Cummings <3627351+jzheaux@users.noreply.github.com >
2026-08-20 11:23:44 -06:00
Josh Cummings
0123ae0981
Deprecate AesBytesEncryptor
...
This commit separates AesBytesEncryptor into two separate
implememtations, allowing for a migration away from default
arrangements that used a null IV
Signed-off-by: Josh Cummings <3627351+jzheaux@users.noreply.github.com >
2026-08-20 11:23:36 -06:00
Josh Cummings
11a648d106
Improve Equivalence Tests
...
This commit adds equals and hashCode implementations as well
as a readResolve implementation to ensure that deserialization
mechanisms can correctly assess the equality of a constnat
and a corresponding deserialized instance. For defense-in-depth
reasons, this commit also favors .equals over == for these
constants.
Signed-off-by: Josh Cummings <3627351+jzheaux@users.noreply.github.com >
2026-08-20 11:23:29 -06:00
Joe Grandja
536e09756c
Bind UnboundIdContainer to loopback address
2026-08-20 11:23:22 -06:00
Joe Grandja
ac15cdbea3
Apply html encoding in DefaultConsentPage
2026-08-20 11:23:14 -06:00
Joe Grandja
ad812aefc4
Provide ability to configure DPoP proof replay
2026-08-20 11:23:08 -06:00
Josh Cummings
d8769fb183
Use Constant-Time Comparison
...
This commit updates password encoders to use a
constant-time comparison method to defend against
timing attacks
Signed-off-by: Josh Cummings <3627351+jzheaux@users.noreply.github.com >
2026-08-20 11:23:02 -06:00
Josh Cummings
ae997a4f46
Use Utf8#isEqual
...
Signed-off-by: Josh Cummings <3627351+jzheaux@users.noreply.github.com >
2026-08-20 11:22:55 -06:00
Josh Cummings
bbc6273abf
Use Constant-Time Equals
...
This commit updates the filter to use constant-time
equals for sensitive material
Signed-off-by: Josh Cummings <3627351+jzheaux@users.noreply.github.com >
2026-08-20 11:22:49 -06:00
Josh Cummings
475af0d3db
Use Constant-Time Equals
...
This commit updates the filter to use constant-time
equals for sensitive material
Signed-off-by: Josh Cummings <3627351+jzheaux@users.noreply.github.com >
2026-08-20 11:22:43 -06:00
Josh Cummings
f8a61e66d1
Add Utf8#isEqual
...
This commit adds a constant-time equals method,
useful for comparing password hashes or other
sensitive material
Signed-off-by: Josh Cummings <3627351+jzheaux@users.noreply.github.com >
2026-08-20 11:22:36 -06:00
Josh Cummings
8830e39073
Use MessageDigest#isEqual
...
This commit favors constant-time comparison
to mitigate timing attacks
Signed-off-by: Josh Cummings <3627351+jzheaux@users.noreply.github.com >
2026-08-20 11:22:31 -06:00
Josh Cummings
304cc21523
Add Tests for User and Device Code
...
Signed-off-by: Josh Cummings <3627351+jzheaux@users.noreply.github.com >
2026-08-20 11:22:25 -06:00
Josh Cummings
7048b08b9c
Update to Spring Data 2026.0.1
...
Closes gh-19490
Signed-off-by: Josh Cummings <3627351+jzheaux@users.noreply.github.com >
2026-08-20 11:21:29 -06:00
Josh Cummings
ff108a49a5
Update to Spring LDAP 4.1.1
...
Closes gh-19491
Signed-off-by: Josh Cummings <3627351+jzheaux@users.noreply.github.com >
2026-08-20 11:21:29 -06:00
Josh Cummings
9a70d73036
Update to Micrometer 1.17.1
...
Closes gh-19489
Signed-off-by: Josh Cummings <3627351+jzheaux@users.noreply.github.com >
2026-08-20 11:21:28 -06:00
Josh Cummings
cf613ad2d3
Update to Reactor 2025.0.7
...
Closes gh-19488
Signed-off-by: Josh Cummings <3627351+jzheaux@users.noreply.github.com >
2026-08-20 11:21:28 -06:00
Josh Cummings
fdec2d7617
Update to Spring Framework 7.0.9
...
Closes gh-19487
Signed-off-by: Josh Cummings <3627351+jzheaux@users.noreply.github.com >
2026-08-20 11:21:28 -06:00
Josh Cummings
748e3c9cf0
Use jspecify Nullable in DPoPProofReplayValidator
...
org.springframework.lang.Nullable is banned by the
bannedNullabilityImports checkstyle rule on this line; the embargoed
commit that introduced this file predates that rule's adoption here.
Switch to org.jspecify.annotations.Nullable to match the rest of the
codebase (already used correctly elsewhere in this same file).
Signed-off-by: Josh Cummings <3627351+jzheaux@users.noreply.github.com >
2026-08-20 11:21:21 -06:00
Josh Cummings
057581584a
Align Null Behavior
...
Previously, ExternalInetAddressMatcher treated a null InetAddress
as external by negating InternalInetAddressMatcher's result.
This commit makes ExternalInetAddressMatcher return false for a
null address, so that neither the internal nor the external
matcher classifies an unknown address as a match.
Signed-off-by: Josh Cummings <3627351+jzheaux@users.noreply.github.com >
2026-08-20 11:21:20 -06:00
Josh Cummings
502ecf9241
Deprecate AesBytesEncryptor
...
This commit separates AesBytesEncryptor into two separate
implememtations, allowing for a migration away from default
arrangements that used a null IV
Signed-off-by: Josh Cummings <3627351+jzheaux@users.noreply.github.com >
2026-08-20 11:21:20 -06:00
Josh Cummings
7db67f923c
Improve Equivalence Tests
...
This commit adds equals and hashCode implementations as well
as a readResolve implementation to ensure that deserialization
mechanisms can correctly assess the equality of a constnat
and a corresponding deserialized instance. For defense-in-depth
reasons, this commit also favors .equals over == for these
constants.
Signed-off-by: Josh Cummings <3627351+jzheaux@users.noreply.github.com >
2026-08-20 11:21:14 -06:00
Joe Grandja
35859220cb
Bind UnboundIdContainer to loopback address
2026-08-20 11:21:14 -06:00
Joe Grandja
3836091fe2
Apply html encoding in DefaultConsentPage
2026-08-20 11:21:14 -06:00
Joe Grandja
4c41928bc7
Provide ability to configure DPoP proof replay
2026-08-20 11:21:13 -06:00
Josh Cummings
61be628ad6
Use Constant-Time Comparison
...
This commit updates password encoders to use a
constant-time comparison method to defend against
timing attacks
Signed-off-by: Josh Cummings <3627351+jzheaux@users.noreply.github.com >
2026-08-20 11:21:06 -06:00
Josh Cummings
e6208a4832
Use Utf8#isEqual
...
Signed-off-by: Josh Cummings <3627351+jzheaux@users.noreply.github.com >
2026-08-20 11:21:06 -06:00
Josh Cummings
01452e328f
Use Constant-Time Equals
...
This commit updates the filter to use constant-time
equals for sensitive material
Signed-off-by: Josh Cummings <3627351+jzheaux@users.noreply.github.com >
2026-08-20 11:21:05 -06:00
Josh Cummings
836190546d
Use Constant-Time Equals
...
This commit updates the filter to use constant-time
equals for sensitive material
Signed-off-by: Josh Cummings <3627351+jzheaux@users.noreply.github.com >
2026-08-20 11:21:05 -06:00
Josh Cummings
9f94fb92c5
Add Utf8#isEqual
...
This commit adds a constant-time equals method,
useful for comparing password hashes or other
sensitive material
Signed-off-by: Josh Cummings <3627351+jzheaux@users.noreply.github.com >
2026-08-20 11:20:58 -06:00
Josh Cummings
47804ee834
Use MessageDigest#isEqual
...
This commit favors constant-time comparison
to mitigate timing attacks
Signed-off-by: Josh Cummings <3627351+jzheaux@users.noreply.github.com >
2026-08-20 11:20:58 -06:00
Josh Cummings
865085e0b0
Add Tests for User and Device Code
...
Signed-off-by: Josh Cummings <3627351+jzheaux@users.noreply.github.com >
2026-08-20 11:20:58 -06:00
Josh Cummings
15a31d7dd7
Check isAnyLocalAddress
...
This commit updates InternalInetAddressMatcher to check
InetAddress#isAnyLocalAddress in order to catch
additional IP addresses
Signed-off-by: Josh Cummings <3627351+jzheaux@users.noreply.github.com >
2026-08-20 11:20:58 -06:00
dependabot[bot]
9d8026fcf3
Bump com.fasterxml.jackson:jackson-bom from 2.22.1 to 2.22.2
...
Bumps [com.fasterxml.jackson:jackson-bom](https://github.com/FasterXML/jackson-bom ) from 2.22.1 to 2.22.2.
- [Commits](https://github.com/FasterXML/jackson-bom/compare/jackson-bom-2.22.1...jackson-bom-2.22.2 )
---
updated-dependencies:
- dependency-name: com.fasterxml.jackson:jackson-bom
dependency-version: 2.22.2
dependency-type: direct:production
update-type: version-update:semver-patch
...
Signed-off-by: dependabot[bot] <support@github.com >
2026-08-20 03:19:14 +00:00
Josh Cummings
4e92ea215c
Merge branch '7.0.x' into 7.1.x
2026-08-19 16:55:38 -06:00
Tadaya Tsuyukubo
d111029078
Prevent sharing SecurityContext across threads
...
`SecurityContextHolderThreadLocalAccessor` currently propagates the
same `SecurityContext` to other threads when Micrometer
Context Propagation is used. This leads to unintended sharing of
mutable state and can cause authentication to leak between threads.
This change updates the accessor to create a new
`SecurityContext` for the target thread while reusing only the
`Authentication` value. Each thread now receives its own
`SecurityContext` instance, preventing cross-thread interference and
aligning with recommended `SecurityContext` usage.
Signed-off-by: Tadaya Tsuyukubo <tadaya@ttddyy.net >
2026-08-19 16:54:43 -06:00
Joe Grandja
7491e37310
Polish gh-19421
2026-08-18 12:11:09 -04:00
Peter Phillips
d90714f07d
Fix to allow null servlet request/response in ServletOAuth2AuthorizedClientExchangeFilterFunction
...
Issue gh-17819
Closes gh-19421
Signed-off-by: Peter Phillips <5099053+petergphillips@users.noreply.github.com >
2026-08-18 11:32:07 -04:00
dependabot[bot]
3cf0867955
Bump tools.jackson:jackson-bom from 3.2.1 to 3.2.2
...
Bumps [tools.jackson:jackson-bom](https://github.com/FasterXML/jackson-bom ) from 3.2.1 to 3.2.2.
- [Commits](https://github.com/FasterXML/jackson-bom/compare/jackson-bom-3.2.1...jackson-bom-3.2.2 )
---
updated-dependencies:
- dependency-name: tools.jackson:jackson-bom
dependency-version: 3.2.2
dependency-type: direct:production
update-type: version-update:semver-patch
...
Signed-off-by: dependabot[bot] <support@github.com >
2026-08-18 03:22:02 +00:00
dependabot[bot]
7f219ea530
Bump ch.qos.logback:logback-classic from 1.6.2 to 1.6.3
...
Bumps [ch.qos.logback:logback-classic](https://github.com/qos-ch/logback ) from 1.6.2 to 1.6.3.
- [Release notes](https://github.com/qos-ch/logback/releases )
- [Commits](https://github.com/qos-ch/logback/compare/v_1.6.2...v_1.6.3 )
---
updated-dependencies:
- dependency-name: ch.qos.logback:logback-classic
dependency-version: 1.6.3
dependency-type: direct:production
update-type: version-update:semver-patch
...
Signed-off-by: dependabot[bot] <support@github.com >
2026-08-18 03:19:31 +00:00
dependabot[bot]
2c0c09b9a6
Bump ch.qos.logback:logback-classic from 1.6.1 to 1.6.2
...
Bumps [ch.qos.logback:logback-classic](https://github.com/qos-ch/logback ) from 1.6.1 to 1.6.2.
- [Release notes](https://github.com/qos-ch/logback/releases )
- [Commits](https://github.com/qos-ch/logback/compare/v_1.6.1...v_1.6.2 )
---
updated-dependencies:
- dependency-name: ch.qos.logback:logback-classic
dependency-version: 1.6.2
dependency-type: direct:production
update-type: version-update:semver-patch
...
Signed-off-by: dependabot[bot] <support@github.com >
2026-08-17 03:27:57 +00:00
Josh Cummings
7cecfbb4db
Merge branch '7.0.x' into 7.1.x
...
Closes gh-19548
2026-08-13 15:58:42 -06:00
dae won
5b923c78ea
Validate Parameter in setPostAuthenticationChecks
...
The null check in setPostAuthenticationChecks of
AbstractUserDetailsReactiveAuthenticationManager asserted the current
field value, which is initialized to a default and can never be null,
instead of the method parameter. As a result, null was silently
accepted and the next authenticate call failed with a raw
NullPointerException instead of failing fast with a clear message.
Closes gh-19276
Signed-off-by: dae won <eodnjs01477@gmail.com >
2026-08-13 15:58:01 -06:00
Josh Cummings
bd4f9a1644
Merge branch '7.0.x' into 7.1.x
...
Closes gh-19545
2026-08-13 15:20:20 -06:00
Tran Ngoc Nhan
65a1099ccb
Correct validation logic in CasAuthenticationToken
...
Closes gh-19368
Signed-off-by: Tran Ngoc Nhan <ngocnhan.tran1996@gmail.com >
2026-08-13 15:19:26 -06:00
Josh Cummings
ade851b2f1
Merge branch '7.0.x' into 7.1.x
...
Closes gh-19539
2026-08-13 11:36:49 -06:00
junhyeong9812
9fdd2dc675
Lowercase username in changePassword lookup
...
InMemoryUserDetailsManager keys its user map on the lower-cased
username everywhere except changePassword, which looked the current
user up with the raw name. A user whose username contains uppercase
letters could therefore not change its password. Lower-case the
lookup key to match the rest of the class.
Closes gh-19336
Signed-off-by: junhyeong9812 <pickjog@gmail.com >
2026-08-13 11:35:59 -06:00
dependabot[bot]
86fe79a848
Bump org.apache.httpcomponents.client5:httpclient5 from 5.6.3 to 5.6.4
...
Bumps [org.apache.httpcomponents.client5:httpclient5](https://github.com/apache/httpcomponents-client ) from 5.6.3 to 5.6.4.
- [Changelog](https://github.com/apache/httpcomponents-client/blob/rel/v5.6.4/RELEASE_NOTES.txt )
- [Commits](https://github.com/apache/httpcomponents-client/compare/rel/v5.6.3...rel/v5.6.4 )
---
updated-dependencies:
- dependency-name: org.apache.httpcomponents.client5:httpclient5
dependency-version: 5.6.4
dependency-type: direct:production
update-type: version-update:semver-patch
...
Signed-off-by: dependabot[bot] <support@github.com >
2026-08-13 03:19:25 +00:00
Josh Cummings
852e81640b
Merge branch '7.0.x' into 7.1.x
2026-08-11 19:40:43 -06:00
Josh Cummings
2aa3c1ab2e
Remove NullAway
...
Issue gh-17816
Signed-off-by: Josh Cummings <3627351+jzheaux@users.noreply.github.com >
2026-08-11 19:40:18 -06:00
Kim Tae Eun
17c58ef088
Remove BeanResolver Null Checks
...
StandardEvaluationContext.setBeanResolver now accepts a nullable
BeanResolver, so the workarounds added for the original limitation
are no longer needed. This removes the explicit null guards (and
equivalent Optional.ofNullable idiom) as well as the
@SuppressWarnings("NullAway") annotations introduced to silence
the false positives.
In addition to the seven sites that explicitly referenced
spring-projects/spring-framework#35371 , two sites in
spring-security-core followed the same workaround pattern without
the comment marker (AbstractSecurityExpressionHandler and
DefaultMethodSecurityExpressionHandler) and have also been
simplified.
Closes gh-17816
Signed-off-by: Kim Tae Eun <snowykte0426@naver.com >
2026-08-11 18:37:09 -07:00
Josh Cummings
fd233120a8
Merge branch '7.0.x' into 7.1.x
2026-08-11 16:19:41 -06:00
Arz Meow
63306ad8ee
Update One-Time Token Docs for Renamed APIs
...
Replace deprecated `UriComponentsBuilder` usage and renamed
`oneTimeTokenLogin` DSL method references in the docs with their
current equivalents.
Closes gh-18367
Signed-off-by: Arz Meow <arthur37231@gmail.com >
2026-08-11 14:47:25 -07:00
Tran Ngoc Nhan
24aec1d002
Fix broken Javadoc links
...
Closes gh-19194
Signed-off-by: Tran Ngoc Nhan <ngocnhan.tran1996@gmail.com >
2026-08-11 14:31:49 -07:00
Tran Ngoc Nhan
863753580c
Fix Broken DefaultLoginPageGeneratingFilter Javadoc Link
...
Use the `javadoc:` macro so the reference resolves correctly.
Signed-off-by: Tran Ngoc Nhan <ngocnhan.tran1996@gmail.com >
2026-08-11 14:31:43 -07:00
Tran Ngoc Nhan
fa92ce3758
Remove Unnecessary AuthorizationDecision Cast
...
Closes gh-19282
2026-08-11 14:30:52 -07:00
Josh Cummings
e7a4349774
Merge branch '7.0.x' into 7.1.x
2026-08-11 14:00:37 -06:00
dependabot[bot]
22f4a5d4da
Bump com.nimbusds:oauth2-oidc-sdk from 11.38.1 to 11.38.2
...
Bumps [com.nimbusds:oauth2-oidc-sdk](https://bitbucket.org/connect2id/oauth-2.0-sdk-with-openid-connect-extensions ) from 11.38.1 to 11.38.2 and com.nimbusds:nimbus-jose-jwt from 10.9 to 10.9.1, which oauth2-oidc-sdk 11.38.2 requires.
- [Changelog](https://bitbucket.org/connect2id/oauth-2.0-sdk-with-openid-connect-extensions/src/master/CHANGELOG.txt )
- [Commits](https://bitbucket.org/connect2id/oauth-2.0-sdk-with-openid-connect-extensions/branches/compare/11.38.2..11.38.1 )
---
updated-dependencies:
- dependency-name: com.nimbusds:oauth2-oidc-sdk
dependency-version: 11.38.2
dependency-type: direct:production
update-type: version-update:semver-patch
- dependency-name: com.nimbusds:nimbus-jose-jwt
dependency-version: 10.9.1
dependency-type: direct:production
update-type: version-update:semver-patch
...
Signed-off-by: dependabot[bot] <support@github.com >
2026-08-11 19:33:41 +00:00
dependabot[bot]
561f1bba0f
Bump com.unboundid:unboundid-ldapsdk from 7.0.4 to 7.0.5
...
Bumps [com.unboundid:unboundid-ldapsdk](https://github.com/pingidentity/ldapsdk ) from 7.0.4 to 7.0.5.
- [Release notes](https://github.com/pingidentity/ldapsdk/releases )
- [Changelog](https://github.com/pingidentity/ldapsdk/blob/master/docs/release-notes.html )
- [Commits](https://github.com/pingidentity/ldapsdk/compare/7.0.4...7.0.5 )
---
updated-dependencies:
- dependency-name: com.unboundid:unboundid-ldapsdk
dependency-version: 7.0.5
dependency-type: direct:production
update-type: version-update:semver-patch
...
Signed-off-by: dependabot[bot] <support@github.com >
2026-08-11 12:00:52 -07:00
dependabot[bot]
268fce2616
Bump antora from 3.2.0-alpha.12 to 3.2.0-rc.2 in /docs
...
---
updated-dependencies:
- dependency-name: antora
dependency-version: 3.2.0-rc.2
dependency-type: direct:production
update-type: version-update:semver-patch
...
Signed-off-by: dependabot[bot] <support@github.com >
2026-08-11 10:27:36 -07:00
dependabot[bot]
c4c547b73b
Bump org.apache.kerby:kerb-simplekdc from 2.1.1 to 2.1.2
...
Bumps org.apache.kerby:kerb-simplekdc from 2.1.1 to 2.1.2.
---
updated-dependencies:
- dependency-name: org.apache.kerby:kerb-simplekdc
dependency-version: 2.1.2
dependency-type: direct:production
update-type: version-update:semver-patch
...
Signed-off-by: dependabot[bot] <support@github.com >
2026-08-11 10:27:26 -07:00
dependabot[bot]
d487048224
Bump ch.qos.logback:logback-classic from 1.5.34 to 1.5.38
...
Bumps [ch.qos.logback:logback-classic](https://github.com/qos-ch/logback ) from 1.5.34 to 1.5.38.
- [Release notes](https://github.com/qos-ch/logback/releases )
- [Commits](https://github.com/qos-ch/logback/compare/v_1.5.34...v_1.5.38 )
---
updated-dependencies:
- dependency-name: ch.qos.logback:logback-classic
dependency-version: 1.5.38
dependency-type: direct:production
update-type: version-update:semver-patch
...
Signed-off-by: dependabot[bot] <support@github.com >
2026-08-11 10:27:10 -07:00
dependabot[bot]
1d15210ae2
Bump actions/checkout from 6.0.3 to 7.0.1
...
Bumps [actions/checkout](https://github.com/actions/checkout ) from 6.0.3 to 7.0.1.
- [Release notes](https://github.com/actions/checkout/releases )
- [Changelog](https://github.com/actions/checkout/blob/main/CHANGELOG.md )
- [Commits](https://github.com/actions/checkout/compare/df4cb1c069e1874edd31b4311f1884172cec0e10...3d3c42e5aac5ba805825da76410c181273ba90b1 )
---
updated-dependencies:
- dependency-name: actions/checkout
dependency-version: 7.0.1
dependency-type: direct:production
update-type: version-update:semver-major
...
Signed-off-by: dependabot[bot] <support@github.com >
2026-08-11 10:26:57 -07:00
dependabot[bot]
5f377e5ec2
Bump @springio/antora-extensions from 1.14.12 to 1.14.13 in /docs
...
Bumps [@springio/antora-extensions](https://github.com/spring-io/antora-extensions ) from 1.14.12 to 1.14.13.
- [Changelog](https://github.com/spring-io/antora-extensions/blob/main/CHANGELOG.adoc )
- [Commits](https://github.com/spring-io/antora-extensions/compare/v1.14.12...v1.14.13 )
---
updated-dependencies:
- dependency-name: "@springio/antora-extensions"
dependency-version: 1.14.13
dependency-type: direct:production
update-type: version-update:semver-patch
...
Signed-off-by: dependabot[bot] <support@github.com >
2026-08-11 10:26:13 -07:00
dependabot[bot]
e107329766
Bump actions/setup-java from 5.2.0 to 5.7.0
...
Bumps [actions/setup-java](https://github.com/actions/setup-java ) from 5.2.0 to 5.7.0.
- [Release notes](https://github.com/actions/setup-java/releases )
- [Commits](https://github.com/actions/setup-java/compare/be666c2fcd27ec809703dec50e508c2fdc7f6654...b6effb05e454b25005698d916606bdc6ffcbf961 )
---
updated-dependencies:
- dependency-name: actions/setup-java
dependency-version: 5.7.0
dependency-type: direct:production
update-type: version-update:semver-minor
...
Signed-off-by: dependabot[bot] <support@github.com >
2026-08-11 10:25:54 -07:00
Josh Cummings
c96eca3ef4
Merge branch '7.0.x' into 7.1.x
2026-08-11 11:09:21 -06:00
Josh Cummings
905b4786e8
Remove Milestone Date Validation
...
Closes gh-19526
Signed-off-by: Josh Cummings <3627351+jzheaux@users.noreply.github.com >
2026-08-11 11:08:05 -06:00
dependabot[bot]
08d3108521
Bump org.junit:junit-bom from 6.1.2 to 6.1.3
...
Bumps [org.junit:junit-bom](https://github.com/junit-team/junit-framework ) from 6.1.2 to 6.1.3.
- [Release notes](https://github.com/junit-team/junit-framework/releases )
- [Commits](https://github.com/junit-team/junit-framework/compare/r6.1.2...r6.1.3 )
---
updated-dependencies:
- dependency-name: org.junit:junit-bom
dependency-version: 6.1.3
dependency-type: direct:production
update-type: version-update:semver-patch
...
Signed-off-by: dependabot[bot] <support@github.com >
2026-08-11 16:40:18 +00:00
Josh Cummings
e3139ff669
Merge branch '7.0.x'
...
# Conflicts:
# .github/workflows/continuous-integration-workflow.yml
# .github/workflows/finalize-release.yml
# .github/workflows/release-scheduler.yml
2026-08-10 15:53:04 -06:00
Josh Cummings
36e7420bd0
Add Release Train Integration
...
This commit adds the build-level configuration required for
release train participation.
See gh-19518
2026-08-10 15:48:02 -06:00
Josh Cummings
f03e612a14
Remove Release Workflows
...
This commit removes workflows for scheduling and
releasing releases in favor of release train support
Closes gh-19518
2026-08-10 15:46:10 -06:00
dependabot[bot]
ebd3f2364c
Bump gradle-wrapper from 9.6.1 to 9.7.0
...
Bumps [gradle-wrapper](https://github.com/gradle/gradle ) from 9.6.1 to 9.7.0.
- [Release notes](https://github.com/gradle/gradle/releases )
- [Commits](https://github.com/gradle/gradle/compare/v9.6.1...v9.7.0 )
---
updated-dependencies:
- dependency-name: gradle-wrapper
dependency-version: 9.7.0
dependency-type: direct:production
update-type: version-update:semver-minor
...
Signed-off-by: dependabot[bot] <support@github.com >
2026-08-10 03:19:32 +00:00
dependabot[bot]
7fd2a726d6
Bump js-yaml from 4.2.0 to 4.3.1 in /javascript
...
Bumps [js-yaml](https://github.com/nodeca/js-yaml ) from 4.2.0 to 4.3.1.
- [Changelog](https://github.com/nodeca/js-yaml/blob/4.3.1/CHANGELOG.md )
- [Commits](https://github.com/nodeca/js-yaml/compare/4.2.0...4.3.1 )
---
updated-dependencies:
- dependency-name: js-yaml
dependency-version: 4.3.1
dependency-type: indirect
...
Signed-off-by: dependabot[bot] <support@github.com >
2026-08-07 01:00:53 +00:00
dependabot[bot]
dfacecdb88
Bump brace-expansion from 1.1.11 to 1.1.18 in /javascript
...
Bumps [brace-expansion](https://github.com/juliangruber/brace-expansion ) from 1.1.11 to 1.1.18.
- [Release notes](https://github.com/juliangruber/brace-expansion/releases )
- [Commits](https://github.com/juliangruber/brace-expansion/compare/1.1.11...v1.1.18 )
---
updated-dependencies:
- dependency-name: brace-expansion
dependency-version: 1.1.18
dependency-type: indirect
...
Signed-off-by: dependabot[bot] <support@github.com >
2026-08-07 00:58:27 +00:00
dependabot[bot]
92b8883fc2
Bump actions/setup-java from 5.6.0 to 5.7.0
...
Bumps [actions/setup-java](https://github.com/actions/setup-java ) from 5.6.0 to 5.7.0.
- [Release notes](https://github.com/actions/setup-java/releases )
- [Commits](https://github.com/actions/setup-java/compare/03ad4de0992f5dab5e18fcb136590ce7c4a0ac95...b6effb05e454b25005698d916606bdc6ffcbf961 )
---
updated-dependencies:
- dependency-name: actions/setup-java
dependency-version: 5.7.0
dependency-type: direct:production
update-type: version-update:semver-minor
...
Signed-off-by: dependabot[bot] <support@github.com >
2026-08-07 00:46:42 +00:00
dependabot[bot]
43731e0523
Bump @springio/antora-extensions from 1.14.12 to 1.14.13 in /docs
...
Bumps [@springio/antora-extensions](https://github.com/spring-io/antora-extensions ) from 1.14.12 to 1.14.13.
- [Changelog](https://github.com/spring-io/antora-extensions/blob/main/CHANGELOG.adoc )
- [Commits](https://github.com/spring-io/antora-extensions/compare/v1.14.12...v1.14.13 )
---
updated-dependencies:
- dependency-name: "@springio/antora-extensions"
dependency-version: 1.14.13
dependency-type: direct:production
update-type: version-update:semver-patch
...
Signed-off-by: dependabot[bot] <support@github.com >
2026-08-07 00:46:03 +00:00
dependabot[bot]
f686a9e313
Bump com.webauthn4j:webauthn4j-core
...
Bumps [com.webauthn4j:webauthn4j-core](https://github.com/webauthn4j/webauthn4j ) from 0.31.8.RELEASE to 0.31.9.RELEASE.
- [Release notes](https://github.com/webauthn4j/webauthn4j/releases )
- [Commits](https://github.com/webauthn4j/webauthn4j/compare/0.31.8.RELEASE...0.31.9.RELEASE )
---
updated-dependencies:
- dependency-name: com.webauthn4j:webauthn4j-core
dependency-version: 0.31.9.RELEASE
dependency-type: direct:production
update-type: version-update:semver-patch
...
Signed-off-by: dependabot[bot] <support@github.com >
2026-08-05 03:17:09 +00:00
Josh Cummings
08d062bdc0
Merge branch '7.0.x'
...
# Conflicts:
# docs/modules/ROOT/pages/features/exploits/http.adoc
2026-08-03 17:53:54 -06:00
Sumit Kumar Das
2c4db99229
Differentiate Forwarded and X-Forwarded headers in proxy docs
...
The proxy server section pointed at RFC 7239 and then told the reader to
configure the application server for the X-Forwarded headers, conflating
the standard Forwarded header with the non-standard X-Forwarded-* set.
Describe the two kinds of headers separately, note that most proxies send
X-Forwarded-* while Spring Framework and servers such as Reactor Netty and
Jetty understand both, and state that the edge proxy has to drop or
overwrite untrusted values for both kinds rather than only one.
Closes gh-19461
Signed-off-by: Sumit Kumar Das <skdas5405@gmail.com >
2026-08-03 17:52:32 -06:00
Josh Cummings
c84875f923
Merge branch 'main' of github.com:spring-projects/spring-security
2026-08-03 16:10:02 -06:00
Josh Cummings
8d452e2c32
Merge branch '7.0.x'
2026-08-03 16:07:26 -06:00
Josh Cummings
0f6f453ea0
Increase Default NimbusJwtDecoder Timeouts to 30 Seconds
...
NimbusJwtDecoder's default RestOperations now respects the JDK's
sun.net.client.defaultConnectTimeout/defaultReadTimeout system properties,
falling back to 30 seconds instead of the previous 500 milliseconds,
matching JwtDecoderProviderConfigurationUtils's existing behavior.
Also documents this default and the RestOperations override in the
reference guide and migration guide (the reference guide's existing
"Configuring Timeouts" section already claimed 30 seconds -- it's been
inaccurate since the 500ms default shipped and is now correct again), and
documents providing a custom JwtDecoderFactory<ClientRegistration> for
OAuth2 Login's ID Token decoding.
Issue gh-19474
Signed-off-by: Josh Cummings <3627351+jzheaux@users.noreply.github.com >
2026-08-03 15:51:41 -06:00
dependabot[bot]
7ec316a030
Bump org.apache.httpcomponents.client5:httpclient5 from 5.6.2 to 5.6.3
...
Bumps [org.apache.httpcomponents.client5:httpclient5](https://github.com/apache/httpcomponents-client ) from 5.6.2 to 5.6.3.
- [Changelog](https://github.com/apache/httpcomponents-client/blob/rel/v5.6.3/RELEASE_NOTES.txt )
- [Commits](https://github.com/apache/httpcomponents-client/compare/rel/v5.6.2...rel/v5.6.3 )
---
updated-dependencies:
- dependency-name: org.apache.httpcomponents.client5:httpclient5
dependency-version: 5.6.3
dependency-type: direct:production
update-type: version-update:semver-patch
...
Signed-off-by: dependabot[bot] <support@github.com >
2026-08-03 03:16:40 +00:00
Josh Cummings
61fae604d2
Merge branch '7.0.x'
2026-07-31 16:03:03 -06:00
Josh Cummings
1eef373ca0
Improve Error Message for Invalid JSR-250 Usage
...
This commit adds an IllegalStateException guard when spring-security-access
is missing and the application is using @EnableGlobalMethodSecurity with
jsr250Enabled.
Issue gh-19441
Signed-off-by: Josh Cummings <3627351+jzheaux@users.noreply.github.com >
2026-07-31 16:01:21 -06:00
jyx-07
7a03cd5a55
Fail fast when spring-security-access is missing
...
The "Move Core Access API" refactoring (gh-17847) relocated
MethodSecurityMetadataSourceAdvisor and MethodSecurityInterceptor
from spring-security-core, a mandatory dependency of
spring-security-config, into the new spring-security-access module,
which spring-security-config only depends on optionally.
GlobalMethodSecuritySelector (backing the deprecated
@EnableGlobalMethodSecurity) and ReactiveMethodSecuritySelector
(backing @EnableReactiveMethodSecurity(useAuthorizationManager =
false)) still unconditionally import configuration that constructs
those classes: MethodSecurityMetadataSourceAdvisorRegistrar in proxy
mode, GlobalMethodSecurityConfiguration in both proxy and aspectj
mode, and ReactiveMethodSecurityConfiguration for the legacy reactive
path. Applications that use any of these deprecated configuration
paths without explicitly adding spring-security-access now fail at
startup with a confusing NoClassDefFoundError deep inside Spring's
configuration-processing machinery, instead of an actionable message.
@EnableMethodSecurity and @EnableReactiveMethodSecurity's default
(AuthorizationManager-based) mode, the non-deprecated replacements,
never reference these classes and are unaffected either way.
Add a ClassUtils.isPresent check to both selectors so that, whenever
a legacy configuration path that needs it is chosen (proxy mode,
aspectj mode, or the legacy reactive interceptor), a missing
spring-security-access dependency now fails fast with a clear
IllegalStateException that names the missing dependency and points
to the supported alternative, rather than a NoClassDefFoundError.
This preserves gh-17847's footprint-reduction intent: the check only
runs for the deprecated legacy annotations, so the majority of
applications using @EnableMethodSecurity see no change in behavior or
dependencies. @EnableGlobalMethodSecurity remains deprecated; this
change adds no new investment in it beyond giving existing users of
it a clear diagnostic instead of a confusing crash.
Closes gh-19441
Signed-off-by: jyx-07 <s25069@gsm.hs.kr >
2026-07-31 16:01:21 -06:00
Josh Cummings
bb59d5c0dd
Merge branch '7.0.x'
...
# Conflicts:
# oauth2/oauth2-authorization-server/src/main/java/org/springframework/security/oauth2/server/authorization/authentication/OAuth2PushedAuthorizationRequestUri.java
2026-07-31 13:22:17 -06:00
Andrey Litvitski
e4fafce066
Fix OAuth2PushedAuthorizationRequestUri parsing
...
OAuth2PushedAuthorizationRequestUri uses Base64URL encoding for the state, which can produce a value containing ___, the same sequence used as the delimiter. As a result, indexOf may locate a delimiter within the state instead of the delimiter preceding the expiration timestamp.
Use lastIndexOf to reliably locate the delimiter before the timestamp without changing the existing request URI format.
Closes gh-19444
Signed-off-by: Andrey Litvitski <andrey1010102008@gmail.com >
2026-07-31 13:19:21 -06:00
Josh Cummings
2104c49597
Add tests for OAuth2PushedAuthorizationRequestUri
...
Adds baseline test coverage for OAuth2PushedAuthorizationRequestUri,
which previously had none: a round-trip via create()/parse() and an
explicit parse() case on a hand-constructed request URI.
See gh-19444.
Signed-off-by: Josh Cummings <3627351+jzheaux@users.noreply.github.com >
2026-07-31 13:19:21 -06:00
Josh Cummings
5bee669ae3
Merge branch '7.0.x'
2026-07-31 12:31:45 -06:00
Josh Cummings
c5b1f78118
Support Testing Against Snapshot Spring LDAP Versions
...
Adds an opt-in override to spring-security-dependencies so it can be
built against a specific Spring LDAP version instead of whatever's
declared in the version catalog, matching the existing pattern for
Spring Framework/Reactor/Spring Data/Micrometer. Passing
-PisOverrideVersionCatalog=true -PspringLdapVersion=X takes precedence
over the catalog. Default behavior (no properties passed) is unchanged.
Closes gh-19481
Signed-off-by: Josh Cummings <3627351+jzheaux@users.noreply.github.com >
2026-07-31 12:31:17 -06:00
dependabot[bot]
f94cef17b8
Bump ch.qos.logback:logback-classic from 1.6.0 to 1.6.1
...
Bumps [ch.qos.logback:logback-classic](https://github.com/qos-ch/logback ) from 1.6.0 to 1.6.1.
- [Release notes](https://github.com/qos-ch/logback/releases )
- [Commits](https://github.com/qos-ch/logback/compare/v_1.6.0...v_1.6.1 )
---
updated-dependencies:
- dependency-name: ch.qos.logback:logback-classic
dependency-version: 1.6.1
dependency-type: direct:production
update-type: version-update:semver-patch
...
Signed-off-by: dependabot[bot] <support@github.com >
2026-07-29 03:16:09 +00:00
dependabot[bot]
25f2e1c2a3
Bump ch.qos.logback:logback-classic from 1.5.38 to 1.6.0
...
Bumps [ch.qos.logback:logback-classic](https://github.com/qos-ch/logback ) from 1.5.38 to 1.6.0.
- [Release notes](https://github.com/qos-ch/logback/releases )
- [Commits](https://github.com/qos-ch/logback/compare/v_1.5.38...v_1.6.0 )
---
updated-dependencies:
- dependency-name: ch.qos.logback:logback-classic
dependency-version: 1.6.0
dependency-type: direct:production
update-type: version-update:semver-minor
...
Signed-off-by: dependabot[bot] <support@github.com >
2026-07-24 03:13:25 +00:00
dependabot[bot]
67a3de25eb
Bump actions/checkout from 7.0.0 to 7.0.1
...
Bumps [actions/checkout](https://github.com/actions/checkout ) from 7.0.0 to 7.0.1.
- [Release notes](https://github.com/actions/checkout/releases )
- [Changelog](https://github.com/actions/checkout/blob/main/CHANGELOG.md )
- [Commits](https://github.com/actions/checkout/compare/9c091bb21b7c1c1d1991bb908d89e4e9dddfe3e0...3d3c42e5aac5ba805825da76410c181273ba90b1 )
---
updated-dependencies:
- dependency-name: actions/checkout
dependency-version: 7.0.1
dependency-type: direct:production
update-type: version-update:semver-patch
...
Signed-off-by: dependabot[bot] <support@github.com >
2026-07-24 00:44:38 +00:00
dependabot[bot]
5bd6b4a570
Bump actions/setup-java from 5.5.0 to 5.6.0
...
Bumps [actions/setup-java](https://github.com/actions/setup-java ) from 5.5.0 to 5.6.0.
- [Release notes](https://github.com/actions/setup-java/releases )
- [Commits](https://github.com/actions/setup-java/compare/0f481fcb613427c0f801b606911222b5b6f3083a...03ad4de0992f5dab5e18fcb136590ce7c4a0ac95 )
---
updated-dependencies:
- dependency-name: actions/setup-java
dependency-version: 5.6.0
dependency-type: direct:production
update-type: version-update:semver-minor
...
Signed-off-by: dependabot[bot] <support@github.com >
2026-07-17 00:45:28 +00:00
dependabot[bot]
08dcb1c0e4
Bump org-jetbrains-kotlin from 2.4.0 to 2.4.10
...
Bumps `org-jetbrains-kotlin` from 2.4.0 to 2.4.10.
Updates `org.jetbrains.kotlin:kotlin-bom` from 2.4.0 to 2.4.10
- [Release notes](https://github.com/JetBrains/kotlin/releases )
- [Changelog](https://github.com/JetBrains/kotlin/blob/master/ChangeLog.md )
- [Commits](https://github.com/JetBrains/kotlin/compare/v2.4.0...v2.4.10 )
Updates `org.jetbrains.kotlin:kotlin-gradle-plugin` from 2.4.0 to 2.4.10
- [Release notes](https://github.com/JetBrains/kotlin/releases )
- [Changelog](https://github.com/JetBrains/kotlin/blob/master/ChangeLog.md )
- [Commits](https://github.com/JetBrains/kotlin/compare/v2.4.0...v2.4.10 )
---
updated-dependencies:
- dependency-name: org.jetbrains.kotlin:kotlin-bom
dependency-version: 2.4.10
dependency-type: direct:production
update-type: version-update:semver-patch
- dependency-name: org.jetbrains.kotlin:kotlin-gradle-plugin
dependency-version: 2.4.10
dependency-type: direct:production
update-type: version-update:semver-patch
...
Signed-off-by: dependabot[bot] <support@github.com >
2026-07-15 03:20:37 +00:00
dependabot[bot]
e1ad5d2392
Bump org.hibernate.orm:hibernate-core from 7.4.4.Final to 7.4.5.Final
...
Bumps [org.hibernate.orm:hibernate-core](https://github.com/hibernate/hibernate-orm ) from 7.4.4.Final to 7.4.5.Final.
- [Release notes](https://github.com/hibernate/hibernate-orm/releases )
- [Changelog](https://github.com/hibernate/hibernate-orm/blob/7.4.5/changelog.txt )
- [Commits](https://github.com/hibernate/hibernate-orm/compare/7.4.4...7.4.5 )
---
updated-dependencies:
- dependency-name: org.hibernate.orm:hibernate-core
dependency-version: 7.4.5.Final
dependency-type: direct:production
update-type: version-update:semver-patch
...
Signed-off-by: dependabot[bot] <support@github.com >
2026-07-14 03:16:11 +00:00
dependabot[bot]
7654aa2f6f
Bump org.junit:junit-bom from 6.1.1 to 6.1.2
...
Bumps [org.junit:junit-bom](https://github.com/junit-team/junit-framework ) from 6.1.1 to 6.1.2.
- [Release notes](https://github.com/junit-team/junit-framework/releases )
- [Commits](https://github.com/junit-team/junit-framework/compare/r6.1.1...r6.1.2 )
---
updated-dependencies:
- dependency-name: org.junit:junit-bom
dependency-version: 6.1.2
dependency-type: direct:production
update-type: version-update:semver-patch
...
Signed-off-by: dependabot[bot] <support@github.com >
2026-07-14 03:15:24 +00:00
dependabot[bot]
a29d4ad5a4
Bump com.nimbusds:oauth2-oidc-sdk from 11.37.2 to 11.38.1
...
Bumps [com.nimbusds:oauth2-oidc-sdk](https://bitbucket.org/connect2id/oauth-2.0-sdk-with-openid-connect-extensions ) from 11.37.2 to 11.38.1.
- [Changelog](https://bitbucket.org/connect2id/oauth-2.0-sdk-with-openid-connect-extensions/src/master/CHANGELOG.txt )
- [Commits](https://bitbucket.org/connect2id/oauth-2.0-sdk-with-openid-connect-extensions/branches/compare/11.38.1..11.37.2 )
---
updated-dependencies:
- dependency-name: com.nimbusds:oauth2-oidc-sdk
dependency-version: 11.38.1
dependency-type: direct:production
update-type: version-update:semver-minor
...
Signed-off-by: dependabot[bot] <support@github.com >
2026-07-13 03:17:43 +00:00
dependabot[bot]
ab33b40f19
Bump org-bouncycastle from 1.84 to 1.85
...
Bumps `org-bouncycastle` from 1.84 to 1.85.
Updates `org.bouncycastle:bcpkix-jdk18on` from 1.84 to 1.85
- [Changelog](https://github.com/bcgit/bc-java/blob/main/docs/releasenotes.html )
- [Commits](https://github.com/bcgit/bc-java/commits )
Updates `org.bouncycastle:bcprov-jdk18on` from 1.84 to 1.85
- [Changelog](https://github.com/bcgit/bc-java/blob/main/docs/releasenotes.html )
- [Commits](https://github.com/bcgit/bc-java/commits )
---
updated-dependencies:
- dependency-name: org.bouncycastle:bcpkix-jdk18on
dependency-version: '1.85'
dependency-type: direct:production
update-type: version-update:semver-minor
- dependency-name: org.bouncycastle:bcprov-jdk18on
dependency-version: '1.85'
dependency-type: direct:production
update-type: version-update:semver-minor
...
Signed-off-by: dependabot[bot] <support@github.com >
2026-07-13 03:16:56 +00:00
dependabot[bot]
d3d6497798
Bump tools.jackson:jackson-bom from 3.2.0 to 3.2.1
...
Bumps [tools.jackson:jackson-bom](https://github.com/FasterXML/jackson-bom ) from 3.2.0 to 3.2.1.
- [Commits](https://github.com/FasterXML/jackson-bom/compare/jackson-bom-3.2.0...jackson-bom-3.2.1 )
---
updated-dependencies:
- dependency-name: tools.jackson:jackson-bom
dependency-version: 3.2.1
dependency-type: direct:production
update-type: version-update:semver-patch
...
Signed-off-by: dependabot[bot] <support@github.com >
2026-07-13 03:14:19 +00:00
dependabot[bot]
6680d42d34
Bump ch.qos.logback:logback-classic from 1.5.37 to 1.5.38
...
Bumps [ch.qos.logback:logback-classic](https://github.com/qos-ch/logback ) from 1.5.37 to 1.5.38.
- [Release notes](https://github.com/qos-ch/logback/releases )
- [Commits](https://github.com/qos-ch/logback/compare/v_1.5.37...v_1.5.38 )
---
updated-dependencies:
- dependency-name: ch.qos.logback:logback-classic
dependency-version: 1.5.38
dependency-type: direct:production
update-type: version-update:semver-patch
...
Signed-off-by: dependabot[bot] <support@github.com >
2026-07-10 03:17:42 +00:00
dependabot[bot]
c2efa64c4d
Bump actions/setup-java from 5.4.0 to 5.5.0
...
Bumps [actions/setup-java](https://github.com/actions/setup-java ) from 5.4.0 to 5.5.0.
- [Release notes](https://github.com/actions/setup-java/releases )
- [Commits](https://github.com/actions/setup-java/compare/1bcf9fb12cf4aa7d266a90ae39939e61372fe520...0f481fcb613427c0f801b606911222b5b6f3083a )
---
updated-dependencies:
- dependency-name: actions/setup-java
dependency-version: 5.5.0
dependency-type: direct:production
update-type: version-update:semver-minor
...
Signed-off-by: dependabot[bot] <support@github.com >
2026-07-10 00:57:47 +00:00
Josh Cummings
0a75d5b785
Merge branch '7.0.x'
2026-07-09 11:02:02 -06:00
Josh Cummings
d2366650ec
Polish Serialization Test
...
This commit makes the version calculation work for
intermediate version numbers like 7.0.5.1
2026-07-09 11:01:06 -06:00
Josh Cummings
39790c0a7e
Merge branch '7.0.x'
2026-07-09 08:44:09 -06:00
Josh Cummings
5338b7a05b
Move Wildcards to Minor Versions
...
This commit targets the major.minor version pair that
matches Spring Security 7.0.x
Signed-off-by: Josh Cummings <3627351+jzheaux@users.noreply.github.com >
2026-07-09 08:43:57 -06:00
Josh Cummings
71f81dede2
Merge branch '7.0.x'
2026-07-09 08:32:45 -06:00
Josh Cummings
bd86d0b233
Add Micrometer to Snapshot Test
...
Signed-off-by: Josh Cummings <3627351+jzheaux@users.noreply.github.com >
2026-07-09 08:32:11 -06:00
Josh Cummings
f8442794a8
Check Only JDK 17
...
This commit removes the extra build for
JDK 21 to save time on builds.
Signed-off-by: Josh Cummings <3627351+jzheaux@users.noreply.github.com >
2026-07-09 08:32:11 -06:00
Josh Cummings
b62affe126
Correct Copyright Headers
...
This commit updates all headers to have
the same date range.
Signed-off-by: Josh Cummings <3627351+jzheaux@users.noreply.github.com >
2026-07-08 17:11:04 -06:00
dependabot[bot]
60e7733d8a
Bump com.fasterxml.jackson:jackson-bom from 2.22.0 to 2.22.1
...
Bumps [com.fasterxml.jackson:jackson-bom](https://github.com/FasterXML/jackson-bom ) from 2.22.0 to 2.22.1.
- [Commits](https://github.com/FasterXML/jackson-bom/compare/jackson-bom-2.22.0...jackson-bom-2.22.1 )
---
updated-dependencies:
- dependency-name: com.fasterxml.jackson:jackson-bom
dependency-version: 2.22.1
dependency-type: direct:production
update-type: version-update:semver-patch
...
Signed-off-by: dependabot[bot] <support@github.com >
2026-07-08 03:15:25 +00:00
dependabot[bot]
2bac0be1d6
Bump org.hibernate.orm:hibernate-core from 7.4.3.Final to 7.4.4.Final
...
Bumps [org.hibernate.orm:hibernate-core](https://github.com/hibernate/hibernate-orm ) from 7.4.3.Final to 7.4.4.Final.
- [Release notes](https://github.com/hibernate/hibernate-orm/releases )
- [Changelog](https://github.com/hibernate/hibernate-orm/blob/7.4.4/changelog.txt )
- [Commits](https://github.com/hibernate/hibernate-orm/compare/7.4.3...7.4.4 )
---
updated-dependencies:
- dependency-name: org.hibernate.orm:hibernate-core
dependency-version: 7.4.4.Final
dependency-type: direct:production
update-type: version-update:semver-patch
...
Signed-off-by: dependabot[bot] <support@github.com >
2026-07-06 03:20:54 +00:00
dependabot[bot]
bb51ad6096
Bump com.webauthn4j:webauthn4j-core
...
Bumps [com.webauthn4j:webauthn4j-core](https://github.com/webauthn4j/webauthn4j ) from 0.31.7.RELEASE to 0.31.8.RELEASE.
- [Release notes](https://github.com/webauthn4j/webauthn4j/releases )
- [Commits](https://github.com/webauthn4j/webauthn4j/compare/0.31.7.RELEASE...0.31.8.RELEASE )
---
updated-dependencies:
- dependency-name: com.webauthn4j:webauthn4j-core
dependency-version: 0.31.8.RELEASE
dependency-type: direct:production
update-type: version-update:semver-patch
...
Signed-off-by: dependabot[bot] <support@github.com >
2026-07-02 03:12:59 +00:00
dependabot[bot]
9161eced5b
Bump org.hibernate.orm:hibernate-core from 7.4.2.Final to 7.4.3.Final
...
Bumps [org.hibernate.orm:hibernate-core](https://github.com/hibernate/hibernate-orm ) from 7.4.2.Final to 7.4.3.Final.
- [Release notes](https://github.com/hibernate/hibernate-orm/releases )
- [Changelog](https://github.com/hibernate/hibernate-orm/blob/7.4.3/changelog.txt )
- [Commits](https://github.com/hibernate/hibernate-orm/compare/7.4.2...7.4.3 )
---
updated-dependencies:
- dependency-name: org.hibernate.orm:hibernate-core
dependency-version: 7.4.3.Final
dependency-type: direct:production
update-type: version-update:semver-patch
...
Signed-off-by: dependabot[bot] <support@github.com >
2026-06-30 03:16:50 +00:00
dependabot[bot]
769fd66ed3
Bump org.apache.httpcomponents.client5:httpclient5 from 5.6.1 to 5.6.2
...
Bumps [org.apache.httpcomponents.client5:httpclient5](https://github.com/apache/httpcomponents-client ) from 5.6.1 to 5.6.2.
- [Changelog](https://github.com/apache/httpcomponents-client/blob/rel/v5.6.2/RELEASE_NOTES.txt )
- [Commits](https://github.com/apache/httpcomponents-client/compare/rel/v5.6.1...rel/v5.6.2 )
---
updated-dependencies:
- dependency-name: org.apache.httpcomponents.client5:httpclient5
dependency-version: 5.6.2
dependency-type: direct:production
update-type: version-update:semver-patch
...
Signed-off-by: dependabot[bot] <support@github.com >
2026-06-30 03:16:17 +00:00
dependabot[bot]
49ecfa71dd
Bump gradle-wrapper from 9.6.0 to 9.6.1
...
Bumps [gradle-wrapper](https://github.com/gradle/gradle ) from 9.6.0 to 9.6.1.
- [Release notes](https://github.com/gradle/gradle/releases )
- [Commits](https://github.com/gradle/gradle/compare/v9.6.0...v9.6.1 )
---
updated-dependencies:
- dependency-name: gradle-wrapper
dependency-version: 9.6.1
dependency-type: direct:production
update-type: version-update:semver-patch
...
Signed-off-by: dependabot[bot] <support@github.com >
2026-06-29 03:18:05 +00:00
dependabot[bot]
c6d41fd1a5
Bump org.junit:junit-bom from 6.1.0 to 6.1.1
...
Bumps [org.junit:junit-bom](https://github.com/junit-team/junit-framework ) from 6.1.0 to 6.1.1.
- [Release notes](https://github.com/junit-team/junit-framework/releases )
- [Commits](https://github.com/junit-team/junit-framework/compare/r6.1.0...r6.1.1 )
---
updated-dependencies:
- dependency-name: org.junit:junit-bom
dependency-version: 6.1.1
dependency-type: direct:production
update-type: version-update:semver-patch
...
Signed-off-by: dependabot[bot] <support@github.com >
2026-06-29 03:16:18 +00:00
dependabot[bot]
316cf90ec2
Bump ch.qos.logback:logback-classic from 1.5.36 to 1.5.37
...
Bumps [ch.qos.logback:logback-classic](https://github.com/qos-ch/logback ) from 1.5.36 to 1.5.37.
- [Release notes](https://github.com/qos-ch/logback/releases )
- [Commits](https://github.com/qos-ch/logback/compare/v_1.5.36...v_1.5.37 )
---
updated-dependencies:
- dependency-name: ch.qos.logback:logback-classic
dependency-version: 1.5.37
dependency-type: direct:production
update-type: version-update:semver-patch
...
Signed-off-by: dependabot[bot] <support@github.com >
2026-06-29 03:15:30 +00:00
dependabot[bot]
f5fbc2b46b
Bump ch.qos.logback:logback-classic from 1.5.35 to 1.5.36
...
Bumps [ch.qos.logback:logback-classic](https://github.com/qos-ch/logback ) from 1.5.35 to 1.5.36.
- [Release notes](https://github.com/qos-ch/logback/releases )
- [Commits](https://github.com/qos-ch/logback/compare/v_1.5.35...v_1.5.36 )
---
updated-dependencies:
- dependency-name: ch.qos.logback:logback-classic
dependency-version: 1.5.36
dependency-type: direct:production
update-type: version-update:semver-patch
...
Signed-off-by: dependabot[bot] <support@github.com >
2026-06-26 03:16:22 +00:00
dependabot[bot]
49d2ebf3cf
Bump org.apache.kerby:kerb-simplekdc from 2.1.1 to 2.1.2
...
Bumps org.apache.kerby:kerb-simplekdc from 2.1.1 to 2.1.2.
---
updated-dependencies:
- dependency-name: org.apache.kerby:kerb-simplekdc
dependency-version: 2.1.2
dependency-type: direct:production
update-type: version-update:semver-patch
...
Signed-off-by: dependabot[bot] <support@github.com >
2026-06-26 03:14:57 +00:00
dependabot[bot]
fc2c927a72
Bump antora from 3.2.0-alpha.12 to 3.2.0-rc.2 in /docs
...
---
updated-dependencies:
- dependency-name: antora
dependency-version: 3.2.0-rc.2
dependency-type: direct:production
update-type: version-update:semver-patch
...
Signed-off-by: dependabot[bot] <support@github.com >
2026-06-26 01:04:48 +00:00
dependabot[bot]
40de3ed6bb
Bump actions/setup-java from 5.3.0 to 5.4.0
...
Bumps [actions/setup-java](https://github.com/actions/setup-java ) from 5.3.0 to 5.4.0.
- [Release notes](https://github.com/actions/setup-java/releases )
- [Commits](https://github.com/actions/setup-java/compare/ad2b38190b15e4d6bdf0c97fb4fca8412226d287...1bcf9fb12cf4aa7d266a90ae39939e61372fe520 )
---
updated-dependencies:
- dependency-name: actions/setup-java
dependency-version: 5.4.0
dependency-type: direct:production
update-type: version-update:semver-minor
...
Signed-off-by: dependabot[bot] <support@github.com >
2026-06-26 01:02:28 +00:00
dependabot[bot]
85e8221ba0
Bump io.spring.nullability:io.spring.nullability.gradle.plugin
...
Bumps [io.spring.nullability:io.spring.nullability.gradle.plugin](https://github.com/spring-gradle-plugins/nullability-plugin ) from 0.0.13 to 0.0.14.
- [Release notes](https://github.com/spring-gradle-plugins/nullability-plugin/releases )
- [Commits](https://github.com/spring-gradle-plugins/nullability-plugin/compare/v0.0.13...v0.0.14 )
---
updated-dependencies:
- dependency-name: io.spring.nullability:io.spring.nullability.gradle.plugin
dependency-version: 0.0.14
dependency-type: direct:production
update-type: version-update:semver-patch
...
Signed-off-by: dependabot[bot] <support@github.com >
2026-06-25 03:16:31 +00:00
dependabot[bot]
7f753a2433
Bump ch.qos.logback:logback-classic from 1.5.34 to 1.5.35
...
Bumps [ch.qos.logback:logback-classic](https://github.com/qos-ch/logback ) from 1.5.34 to 1.5.35.
- [Release notes](https://github.com/qos-ch/logback/releases )
- [Commits](https://github.com/qos-ch/logback/compare/v_1.5.34...v_1.5.35 )
---
updated-dependencies:
- dependency-name: ch.qos.logback:logback-classic
dependency-version: 1.5.35
dependency-type: direct:production
update-type: version-update:semver-patch
...
Signed-off-by: dependabot[bot] <support@github.com >
2026-06-24 03:14:02 +00:00
dependabot[bot]
ed7ae7969e
Bump org.hibernate.orm:hibernate-core from 7.4.1.Final to 7.4.2.Final
...
Bumps [org.hibernate.orm:hibernate-core](https://github.com/hibernate/hibernate-orm ) from 7.4.1.Final to 7.4.2.Final.
- [Release notes](https://github.com/hibernate/hibernate-orm/releases )
- [Changelog](https://github.com/hibernate/hibernate-orm/blob/7.4.2/changelog.txt )
- [Commits](https://github.com/hibernate/hibernate-orm/compare/7.4.1...7.4.2 )
---
updated-dependencies:
- dependency-name: org.hibernate.orm:hibernate-core
dependency-version: 7.4.2.Final
dependency-type: direct:production
update-type: version-update:semver-patch
...
Signed-off-by: dependabot[bot] <support@github.com >
2026-06-22 03:16:09 +00:00
dependabot[bot]
4ddef4ed83
Bump gradle-wrapper from 9.5.1 to 9.6.0
...
Bumps [gradle-wrapper](https://github.com/gradle/gradle ) from 9.5.1 to 9.6.0.
- [Release notes](https://github.com/gradle/gradle/releases )
- [Commits](https://github.com/gradle/gradle/compare/v9.5.1...v9.6.0 )
---
updated-dependencies:
- dependency-name: gradle-wrapper
dependency-version: 9.6.0
dependency-type: direct:production
update-type: version-update:semver-minor
...
Signed-off-by: dependabot[bot] <support@github.com >
2026-06-19 03:20:36 +00:00
dependabot[bot]
abb8aa54d8
Bump org-opensaml5 from 5.2.2 to 5.2.3
...
Bumps `org-opensaml5` from 5.2.2 to 5.2.3.
Updates `org.opensaml:opensaml-saml-api` from 5.2.2 to 5.2.3
Updates `org.opensaml:opensaml-saml-impl` from 5.2.2 to 5.2.3
---
updated-dependencies:
- dependency-name: org.opensaml:opensaml-saml-api
dependency-version: 5.2.3
dependency-type: direct:production
update-type: version-update:semver-patch
- dependency-name: org.opensaml:opensaml-saml-impl
dependency-version: 5.2.3
dependency-type: direct:production
update-type: version-update:semver-patch
...
Signed-off-by: dependabot[bot] <support@github.com >
2026-06-19 03:17:49 +00:00
dependabot[bot]
deb298ee81
Bump actions/checkout from 6.0.3 to 7.0.0
...
Bumps [actions/checkout](https://github.com/actions/checkout ) from 6.0.3 to 7.0.0.
- [Release notes](https://github.com/actions/checkout/releases )
- [Changelog](https://github.com/actions/checkout/blob/main/CHANGELOG.md )
- [Commits](https://github.com/actions/checkout/compare/df4cb1c069e1874edd31b4311f1884172cec0e10...9c091bb21b7c1c1d1991bb908d89e4e9dddfe3e0 )
---
updated-dependencies:
- dependency-name: actions/checkout
dependency-version: 7.0.0
dependency-type: direct:production
update-type: version-update:semver-major
...
Signed-off-by: dependabot[bot] <support@github.com >
2026-06-19 01:03:52 +00:00
dependabot[bot]
3565d9bd9d
Bump js-yaml from 4.1.1 to 4.2.0 in /javascript
...
Bumps [js-yaml](https://github.com/nodeca/js-yaml ) from 4.1.1 to 4.2.0.
- [Changelog](https://github.com/nodeca/js-yaml/blob/master/CHANGELOG.md )
- [Commits](https://github.com/nodeca/js-yaml/commits )
---
updated-dependencies:
- dependency-name: js-yaml
dependency-version: 4.2.0
dependency-type: indirect
...
Signed-off-by: dependabot[bot] <support@github.com >
2026-06-19 01:02:56 +00:00
dependabot[bot]
827a689ef8
Bump actions/setup-java from 5.2.0 to 5.3.0
...
Bumps [actions/setup-java](https://github.com/actions/setup-java ) from 5.2.0 to 5.3.0.
- [Release notes](https://github.com/actions/setup-java/releases )
- [Commits](https://github.com/actions/setup-java/compare/be666c2fcd27ec809703dec50e508c2fdc7f6654...ad2b38190b15e4d6bdf0c97fb4fca8412226d287 )
---
updated-dependencies:
- dependency-name: actions/setup-java
dependency-version: 5.3.0
dependency-type: direct:production
update-type: version-update:semver-minor
...
Signed-off-by: dependabot[bot] <support@github.com >
2026-06-19 00:46:33 +00:00
dependabot[bot]
43f958e058
Bump esbuild from 0.25.0 to 0.28.1 in /javascript
...
Bumps [esbuild](https://github.com/evanw/esbuild ) from 0.25.0 to 0.28.1.
- [Release notes](https://github.com/evanw/esbuild/releases )
- [Changelog](https://github.com/evanw/esbuild/blob/main/CHANGELOG-2025.md )
- [Commits](https://github.com/evanw/esbuild/compare/v0.25.0...v0.28.1 )
---
updated-dependencies:
- dependency-name: esbuild
dependency-version: 0.28.1
dependency-type: direct:development
...
Signed-off-by: dependabot[bot] <support@github.com >
2026-06-14 01:16:55 +00:00
dependabot[bot]
5594fc018f
Bump com.unboundid:unboundid-ldapsdk from 7.0.4 to 7.0.5
...
Bumps [com.unboundid:unboundid-ldapsdk](https://github.com/pingidentity/ldapsdk ) from 7.0.4 to 7.0.5.
- [Release notes](https://github.com/pingidentity/ldapsdk/releases )
- [Changelog](https://github.com/pingidentity/ldapsdk/blob/master/docs/release-notes.html )
- [Commits](https://github.com/pingidentity/ldapsdk/commits )
---
updated-dependencies:
- dependency-name: com.unboundid:unboundid-ldapsdk
dependency-version: 7.0.5
dependency-type: direct:production
update-type: version-update:semver-patch
...
Signed-off-by: dependabot[bot] <support@github.com >
2026-06-12 03:17:11 +00:00
dependabot[bot]
bf06d19225
Bump com.webauthn4j:webauthn4j-core
...
Bumps [com.webauthn4j:webauthn4j-core](https://github.com/webauthn4j/webauthn4j ) from 0.31.6.RELEASE to 0.31.7.RELEASE.
- [Release notes](https://github.com/webauthn4j/webauthn4j/releases )
- [Commits](https://github.com/webauthn4j/webauthn4j/compare/0.31.6.RELEASE...0.31.7.RELEASE )
---
updated-dependencies:
- dependency-name: com.webauthn4j:webauthn4j-core
dependency-version: 0.31.7.RELEASE
dependency-type: direct:production
update-type: version-update:semver-patch
...
Signed-off-by: dependabot[bot] <support@github.com >
2026-06-10 03:17:13 +00:00
dependabot[bot]
d511a4badb
Bump org.hibernate.orm:hibernate-core from 7.4.0.Final to 7.4.1.Final
...
Bumps [org.hibernate.orm:hibernate-core](https://github.com/hibernate/hibernate-orm ) from 7.4.0.Final to 7.4.1.Final.
- [Release notes](https://github.com/hibernate/hibernate-orm/releases )
- [Changelog](https://github.com/hibernate/hibernate-orm/blob/7.4.1/changelog.txt )
- [Commits](https://github.com/hibernate/hibernate-orm/compare/7.4.0...7.4.1 )
---
updated-dependencies:
- dependency-name: org.hibernate.orm:hibernate-core
dependency-version: 7.4.1.Final
dependency-type: direct:production
update-type: version-update:semver-patch
...
Signed-off-by: dependabot[bot] <support@github.com >
2026-06-10 03:15:52 +00:00
Joe Grandja
038a6601d8
Merge branch '7.0.x'
2026-06-09 14:30:59 -04:00
Joe Grandja
57c2af4900
Merge branch '6.5.x' into 7.0.x
2026-06-09 14:30:37 -04:00
github-actions[bot]
4690f1bb8a
Next development version
2026-06-09 16:39:34 +00:00
github-actions[bot]
6da4ea0d0d
Next development version
2026-06-09 16:06:39 +00:00
github-actions[bot]
8f69721f24
Next development version
2026-06-09 16:02:59 +00:00
github-actions[bot]
acd131c3d1
Release 7.0.6
2026-06-09 15:31:10 +00:00
github-actions[bot]
73b077790f
Release 6.5.11
2026-06-09 15:25:02 +00:00