Skip to content

Conversation

@renovate
Copy link
Contributor

@renovate renovate bot commented Jun 5, 2025

This PR contains the following updates:

Package Change Age Confidence
org.springframework.cloud:spring-cloud-starter-openfeign (source) 4.2.1 -> 4.3.0 age confidence
org.springframework.cloud:spring-cloud-context (source) 4.2.1 -> 4.3.0 age confidence
org.springframework.boot:spring-boot-starter-validation (source) 3.4.4 -> 3.5.7 age confidence
org.springframework.security:spring-security-web (source) 6.4.4 -> 6.5.6 age confidence
org.springframework.security:spring-security-test (source) 6.4.4 -> 6.5.6 age confidence
org.springframework.security:spring-security-taglibs (source) 6.4.4 -> 6.5.6 age confidence
org.springframework.security:spring-security-saml2-service-provider (source) 6.4.4 -> 6.5.6 age confidence
org.springframework.security:spring-security-rsocket (source) 6.4.4 -> 6.5.6 age confidence
org.springframework.security:spring-security-oauth2-resource-server (source) 6.4.4 -> 6.5.6 age confidence
org.springframework.security:spring-security-oauth2-jose (source) 6.4.4 -> 6.5.6 age confidence
org.springframework.security:spring-security-oauth2-core (source) 6.4.4 -> 6.5.6 age confidence
org.springframework.security:spring-security-oauth2-client (source) 6.4.4 -> 6.5.6 age confidence
org.springframework.security:spring-security-messaging (source) 6.4.4 -> 6.5.6 age confidence
org.springframework.security:spring-security-ldap (source) 6.4.4 -> 6.5.6 age confidence
org.springframework.security:spring-security-data (source) 6.4.4 -> 6.5.6 age confidence
org.springframework.security:spring-security-crypto (source) 6.4.4 -> 6.5.6 age confidence
org.springframework.security:spring-security-config (source) 6.4.4 -> 6.5.6 age confidence
org.springframework.security:spring-security-cas (source) 6.4.4 -> 6.5.6 age confidence
org.springframework.security:spring-security-aspects (source) 6.4.4 -> 6.5.6 age confidence
org.springframework.security:spring-security-acl (source) 6.4.4 -> 6.5.6 age confidence
org.springframework.security:spring-security-core (source) 6.4.4 -> 6.5.6 age confidence
org.springframework.boot 3.4.4 -> 3.5.7 age confidence

Release Notes

spring-cloud/spring-cloud-openfeign (org.springframework.cloud:spring-cloud-starter-openfeign)

v4.3.0: 4.3.0

⭐ New Features

  • PagedModel support in PageJacksonModule #​1193

❤️ Contributors

Thank you to all the contributors who worked on this release:

@​bruce-stewart and @​dependabot[bot]

v4.2.2: 4.2.2

❤️ Contributors

Thank you to all the contributors who worked on this release:

@​HyeongDo-Myeong and @​dependabot[bot]

spring-cloud/spring-cloud-commons (org.springframework.cloud:spring-cloud-context)

v4.2.3: 4.2.3

🐞 Bug Fixes

  • Wrong set of active profiles as property substitution does not take place inside values #​1580

❤️ Contributors

Thank you to all the contributors who worked on this release:

@​dependabot[bot] and @​wind57

v4.2.2: 4.2.2

🐞 Bug Fixes

  • Use okhttp-bom for okhttp version management #​1479

❤️ Contributors

Thank you to all the contributors who worked on this release:

@​dependabot[bot]

spring-projects/spring-boot (org.springframework.boot:spring-boot-starter-validation)

v3.5.7

v3.5.6

🐞 Bug Fixes
  • Quoted -D arguments break system property resolution on Linux with Spring AOT #​47166
  • Groovy Templates fails with an NPE when rendering an auto new line #​47139
  • available() does not behave correctly when reading stored entries from a NestedJarFile #​47057
  • spring-boot-docker-compose doesn't create service connections when image has registry host but not project #​47019
  • Flyway Ignore Migration Patterns setting can't be set to an empty string #​47013
📔 Documentation
  • Default value of server.tomcat.resource.cache-ttl is not documented #​47253
  • Document Java 25 support #​47245
  • Fix links to Flyway reference documentation #​46988
  • Clarify Javadoc of Customizer interfaces about overriding behavior #​46942
🔨 Dependency Upgrades
❤️ Contributors

Thank you to all the contributors who worked on this release:

@​Chanwon-Seo, @​doljae, @​izeye, and @​quaff

v3.5.5

🐞 Bug Fixes
  • Hazelcast health indicator reports the wrong status when Hazelcast has shut down due to an out-of-memory error #​46909
  • Performance critical tracing code has high overhead due to the use of the Stream API #​46844
  • SpringLiquibaseCustomizer is exposed outside its defined visibility scope #​46758
  • Race condition in OutputCapture can result in stale data #​46721
  • Auto-configured WebClient no longer uses context's ReactorResourceFactory #​46673
  • Default value not detected for a field annoted with @Name #​46666
  • Missing metadata when using @Name with a constructor-bound property #​46663
  • Missing property for Spring Authorization Server's PAR endpoint #​46641
  • Property name is incorrect when reporting a mis-configured OAuth 2 Resource Server JWT public key location #​46636
  • Memory not freed on context restart in JpaMetamodel#CACHE with spring.main.lazy-initialization=true #​46634
  • Auto-configured MockMvc ignores @FilterRegistration annotation #​46605
  • Failure to discover default value for a primitive should not lead to document its default value #​46561
📔 Documentation
  • Kotlin samples for configuration metadata are in the wrong package #​46857
  • Observability examples in the reference guide are missing the Kotlin version #​46798
  • Align method descriptions for SslOptions getCiphers and getEnabledProtocols with @returns #​46769
  • Tracing samples in the reference guide are missing the Kotlin version #​46767
  • Improve Virtual Threads section to mention the changes in Java 24 #​46610
  • spring.test.webtestclient.timeout is not documented #​46588
  • spring-boot-test-autoconfigure should use the configuration properties annotation processor like other modules #​46585
  • Adapt deprecation level for management.health.influxdb.enabled #​46580
  • spring.test.mockmvc properties are not documented #​46578
🔨 Dependency Upgrades
❤️ Contributors

Thank you to all the contributors who worked on this release:

@​Kguswo, @​deejay1, @​ganjisriver, @​izeye, @​jetflo, @​ngocnhan-tran1996, @​nicolasgarea, @​nosan, @​prishedko, @​quaff, @​schmidti159, @​scordio, @​shakuzen, @​tommyk-gears, @​zahra7, and @​zakaria-shahen

v3.5.4

🐞 Bug Fixes
  • LambdaSafe.withFilter is not public #​46474
  • Executable JAR application class encounters performance issues when used with Palo Alto Network Cortex XDR agent #​46402
  • Runtime dependencies are missing from aotCompileClasspath and aotTestCompileClasspath when using Kotlin #​46398
  • Additional fields for structured JSON logging incompatible with nested ecs logging in 3.5.x #​46351
  • Change in DefaultErrorAttributes alters the shape of API validation error responses #​46260
  • jdbc.connections.active and jdbc.connections.idle metrics are not available when using Hikari in a native image #​46225
  • developmentOnly and testAndDevelopmentOnly dependencies may prevent implementation dependencies from being included in the uber-jar #​46205
  • Hash calculation for uber archive entries that require unpacking is inefficient #​46203
  • Permissions are applied inconsistently when building uber archives with Gradle #​46194
  • Environment variables using legacy dash format can no longer be bound #​46184
  • EmbeddedWebServerFactoryCustomizerAutoConfiguration fails when undertow-core is on the classpath and undertow-servlet is not #​46180
  • Executable JAR application class encounters performance issues #​46177
  • Executable JAR application class encounters performance issues #​46176
  • Setting spring.reactor.context-propagation has no effect when lazy initialization is enabled #​46174
  • Setting spring.netty.leak-detection has no effect when lazy initialization is enabled #​46170
  • SslInfo does not use its Clock when checking certificate validity #​46011
📔 Documentation
  • Fix description of spring.batch.job.enabled #​46247
  • Fix broken Kotlin examples in reference documentation #​46168
  • Add Logback Access Reactor Netty to community starters #​46060
🔨 Dependency Upgrades
❤️ Contributors

Thank you to all the contributors who worked on this release:

@​Dockerel, @​PiyalAhmed, @​benelog, @​dmitrysulman, @​izeye, @​ngocnhan-tran1996, @​nosan, and @​quaff

v3.5.3

🐞 Bug Fixes
  • Binder context does not restore previous source causing missing data on Spring Boot 3.5 or above #​46040

v3.5.2

🐞 Bug Fixes
  • IllegalArgumentException: 'name' must not be null thrown when property source filtering applied twice #​46032

v3.5.1

⚠️ Noteworthy Changes
  • This release upgrades to Tomcat 10.1.42 which has introduced limits for part count and header size in multipart/form-data requests. These limits can be customized using server.tomcat.max-part-count and server.tomcat.max-part-header-size respectively.
⭐ New Features
  • Allow Specifying ConfigData.Options On ConfigDataEnvironmentContributors #​42932
🐞 Bug Fixes
  • Executable JAR application class encounters performance issues when classpath URLs reference a host #​46028
  • Loading from spring.factories may fail with a ClassNotFoundException when the TCCL changes between calls #​46019
  • spring.couchbase.authentication.jks.private-key-password has no effect #​46006
  • Actuator heapdump endpoint is failing on modern OpenJ9 JVMs #​46005
  • UnboundConfigurationPropertiesException is no longer thrown from IndexedElementsBinder #​45994
  • DataSouceBuilder can fail with a NPE when the driver is null #​45992
  • JSON writer incorrectly escapes forward slash which can cause structure logging issues #​45980
  • ManagementContextAutoConfiguration adds a property source that degrades binding performance #​45968
  • ClientHttpConnectorAutoConfiguration fails to load when 'java.net.http.HttpClient' is unavailable #​45955
  • It is not possible to opt-out of profile validation or use profile names that contain '.' #​45947
  • GraphQlProperties.DeprecatedSse is not annotated as deprecated #​45878
  • SpringApplication.setEnvironmentPrefix is ignored when reading MANAGEMENT_SERVER_PORT #​45857
  • Write and delete operations no longer work in the Cloud Foundry actuator support with Spring Security due to CSRF protection #​45848
  • ConditionalOnAvailableEndpoint does not use the ConditionContext's ClassLoader to load exposure outcome contributors #​45803
  • Binding no longer works with sytem environment properties that are not upper case #​45741
  • ManagementWebServerFactoryCustomizer and ManagementErrorPageCustomizer should not have the same order #​45736
  • Default version of Awailitility is not compatible with Kotlin 1.9 baseline #​45673
  • Spring Boot 3.5's dependency management should have been upgraded to Lettuce 6.6.0.RELEASE #​45670
  • Spring Boot 3.5's dependency management should have been upgraded to Jedis 6.0.0 #​45669
  • SAML2 autoconfiguration is not imported by @WebMvcTest #​45666
  • Spring Boot 3.5's dependency management should have been upgraded to MongoDB 5.5.0 #​45660
📔 Documentation
  • Fix Docker security options links in Packaging OCI images sections #​46021
  • Improve documentation for configuring Spring Security with '/error' #​46009
  • Timestamps in Retrieving Audit Events examples do not match the accompanying text #​45997
  • Add SSL response structure to actuator info endpoint documentation #​45921
  • Update javadoc of test slice annotations to suggest MockitoBean rather than MockBean #​45915
  • Include configuration classes from all modules in the "Auto-configuration Classes" appendix #​45863
  • Links to Testcontainers javadoc for many classes not in the core testcontainers module do not work #​45844
  • Update documentation to reflect changes in TestRestTemplate's default redirect behavior #​45842
  • Deprecation replacement for spring.codec.* properties has a typo #​45743
  • Gradle Shadow Plugin link in the reference guide is outdated #​45740
  • Example of using prometheus-metrics-exporter-pushgateway has wrong artifactId #​45684
  • Document use of git-commit-id-maven-plugin consistently #​45683
  • Update javadoc of Configurer classes that apply sensible defaults to describe how they're typically used #​45656
🔨 Dependency Upgrades
❤️ Contributors

Thank you to all the contributors who worked on this release:

@​Peksa, @​Rutujakolte03, @​chanbinme, @​csbiy, @​davidlj95, @​izeye, @​juliojgd, @​ngocnhan-tran1996, @​nicolasgarea, @​nosan, @​quaff, @​shekharAggarwal, @​tanruian, and @​wonyongg

v3.5.0

Full release notes for Spring Boot 3.5 are available on the wiki.

⭐ New Features
  • Make heapdump endpoint restricted by default #​45624
  • Remove SSL status tag from metrics #​45602
  • Remove 'spring.http.client' deprecation and change 'spring.http.reactiveclient.settings' to 'spring.http.reactiveclient' #​45507
🐞 Bug Fixes
  • Unable to override/set nested ConfigurationProperties by passing as a system property #​45639
  • ValidationAutoConfiguration triggers early initialization of properties binding #​45618
  • Micrometer "enable" annotations property does not cover observed aspect #​45617
  • spring.graphql.sse.timeout is no longer exposed #​45613
  • SpringApplication.setEnvironmentPrefix is ignored when reading SPRING_PROFILES_ACTIVE #​45549
  • IllegalStateException when extracting using layers a module with no code of its own #​45449
  • Removed spring.batch.initialize-schema property is still considered #​45380
  • ReactorHttpClientBuilder does not offer a factory method to create the HttpClient #​45378
  • Suggested values for spring.jpa.hibernate.ddl-auto are not aligned with Hibernate #​45351
  • Custom default units declared on a field are ignored when binding properties in a native image #​45347
  • DockerRegistryConfigAuthentication uses the wrong serverUrl as a fallback for the Credentials helper #​45345
  • Various spring.datasource properties are mistakenly marked as ignored #​45342
  • JerseyWebApplicationInitializer always gets loaded, setting a ServletContext initParameter #​45297
  • DockerRegistryConfigAuthentication does not align with Docker CLI #​45292
  • Unlike the Docker CLI, "\x00" characters are not trimmed from a decoded Docker Registry password #​45290
  • CloudFoundry security matcher logs a warning due to use of the 'ignoring()' method #​32622
📔 Documentation
  • Document the java info contribution #​45634
  • Document the process info contribution #​45632
  • Document the os info contribution #​45630
  • Document typical spring.application.group and name use #​45628
  • Document that bean methods should be static when annotated with @ConfigurationPropertiesBinding #​45626
  • Document the way that primary Kotlin constructors are used when binding #​45553
  • Improve "profile" reference documentation with additional admonitions #​45551
  • Improve setEnvironmentPrefix(...) reference documentation #​45376
  • Document all the available Testcontainers integrations #​45367
  • Document when a spring.config.import value is relative and when it is fixed #​45363
  • Update org.cyclonedx.bom version in docs to 2.3.0 #​45320
  • Update link to "Parameter Name Retention" section of Spring Framework's release notes #​45299
🔨 Dependency Upgrades

Configuration

📅 Schedule: Branch creation - "after 7am and before 11am every weekday" in timezone Europe/London, Automerge - "after 8am and before 11am every Tuesday" in timezone Europe/London.

🚦 Automerge: Disabled by config. Please merge this manually once you are satisfied.

Rebasing: Whenever PR is behind base branch, or you tick the rebase/retry checkbox.

👻 Immortal: This PR will be recreated if closed unmerged. Get config help if that's undesired.


  • If you want to rebase/retry this PR, check this box

This PR was generated by Mend Renovate. View the repository job log.

@renovate renovate bot added the dependencies Pull requests that update a dependency file label Jun 5, 2025
@renovate renovate bot force-pushed the renovate/spring-upgrade-non-major branch 10 times, most recently from b014f24 to 124bae5 Compare June 16, 2025 07:51
@renovate renovate bot force-pushed the renovate/spring-upgrade-non-major branch 9 times, most recently from 29de791 to f60aa85 Compare June 23, 2025 12:42
@renovate renovate bot force-pushed the renovate/spring-upgrade-non-major branch 3 times, most recently from a1fdbac to 25b4d9a Compare June 30, 2025 13:57
@renovate renovate bot force-pushed the renovate/spring-upgrade-non-major branch from 25b4d9a to 2f1210d Compare July 2, 2025 11:09
@renovate renovate bot force-pushed the renovate/spring-upgrade-non-major branch from 2f1210d to 5a8df53 Compare July 7, 2025 11:01
@renovate renovate bot force-pushed the renovate/spring-upgrade-non-major branch from 54a62ae to 3297b94 Compare August 26, 2025 09:13
@renovate renovate bot force-pushed the renovate/spring-upgrade-non-major branch from 3297b94 to f963ca0 Compare September 1, 2025 13:34
@renovate renovate bot force-pushed the renovate/spring-upgrade-non-major branch from f963ca0 to d81014f Compare September 2, 2025 10:43
@renovate renovate bot force-pushed the renovate/spring-upgrade-non-major branch from d81014f to 631924c Compare September 3, 2025 12:41
@renovate renovate bot force-pushed the renovate/spring-upgrade-non-major branch from 631924c to 42da5dc Compare September 15, 2025 13:08
@renovate renovate bot force-pushed the renovate/spring-upgrade-non-major branch from 42da5dc to e653c30 Compare September 16, 2025 11:06
@renovate renovate bot force-pushed the renovate/spring-upgrade-non-major branch from e653c30 to 10da919 Compare September 17, 2025 16:30
@renovate renovate bot force-pushed the renovate/spring-upgrade-non-major branch from 10da919 to 4afef51 Compare September 18, 2025 15:50
@renovate renovate bot force-pushed the renovate/spring-upgrade-non-major branch from 4afef51 to f0b6811 Compare September 24, 2025 12:59
@renovate renovate bot force-pushed the renovate/spring-upgrade-non-major branch 2 times, most recently from 89a5c25 to 020121f Compare October 7, 2025 05:55
@renovate renovate bot force-pushed the renovate/spring-upgrade-non-major branch 2 times, most recently from 24f02fa to 25ce354 Compare October 8, 2025 12:56
@renovate renovate bot force-pushed the renovate/spring-upgrade-non-major branch from 25ce354 to 15f88e7 Compare October 14, 2025 16:42
@renovate renovate bot force-pushed the renovate/spring-upgrade-non-major branch 2 times, most recently from 368075b to cd31f38 Compare October 20, 2025 23:26
@renovate renovate bot force-pushed the renovate/spring-upgrade-non-major branch from cd31f38 to 55e07e7 Compare October 23, 2025 15:11
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

Projects

None yet

Development

Successfully merging this pull request may close these issues.

0 participants