Skip to content

Update spring security to v7 - #1032

Open
renovate[bot] wants to merge 1 commit into
masterfrom
renovate/major-spring-security
Open

Update spring security to v7#1032
renovate[bot] wants to merge 1 commit into
masterfrom
renovate/major-spring-security

Conversation

@renovate

@renovate renovate Bot commented Apr 7, 2026

Copy link
Copy Markdown
Contributor

ℹ️ Note

This PR body was truncated due to platform limits.

This PR contains the following updates:

Package Change Age Confidence
org.springframework.security:spring-security-web (source) 6.0.87.1.0 age confidence
org.springframework.security:spring-security-test (source) 6.0.87.1.0 age confidence
org.springframework.security:spring-security-taglibs (source) 6.0.87.1.0 age confidence
org.springframework.security:spring-security-saml2-service-provider (source) 6.0.87.1.0 age confidence
org.springframework.security:spring-security-rsocket (source) 6.0.87.1.0 age confidence
org.springframework.security:spring-security-oauth2-resource-server (source) 6.0.87.1.0 age confidence
org.springframework.security:spring-security-oauth2-jose (source) 6.0.87.1.0 age confidence
org.springframework.security:spring-security-oauth2-core (source) 6.0.87.1.0 age confidence
org.springframework.security:spring-security-oauth2-client (source) 6.0.87.1.0 age confidence
org.springframework.security:spring-security-messaging (source) 6.0.87.1.0 age confidence
org.springframework.security:spring-security-ldap (source) 6.0.87.1.0 age confidence
org.springframework.security:spring-security-data (source) 6.0.87.1.0 age confidence
org.springframework.security:spring-security-crypto (source) 6.0.87.1.0 age confidence
org.springframework.security:spring-security-config (source) 6.0.87.1.0 age confidence
org.springframework.security:spring-security-cas (source) 6.0.87.1.0 age confidence
org.springframework.security:spring-security-aspects (source) 6.0.87.1.0 age confidence
org.springframework.security:spring-security-acl (source) 6.0.87.1.0 age confidence
org.springframework.security:spring-security-core (source) 6.0.87.1.0 age confidence

Release Notes

spring-projects/spring-security (org.springframework.security:spring-security-web)

v7.1.0

Compare Source

🪲 Bug Fixes
  • Opaque token introspectors should not allow empty credentials #​19201
🔨 Dependency Upgrades
  • Bump @springio/antora-extensions from 1.14.11 to 1.14.12 in /docs #​19235
  • Bump actions/checkout from 6.0.2 to 6.0.3 #​19271
  • Bump antora from 3.2.0-alpha.11 to 3.2.0-alpha.12 in /docs #​19181
  • Bump ch.qos.logback:logback-classic from 1.5.32 to 1.5.33 #​19228
  • Bump ch.qos.logback:logback-classic from 1.5.33 to 1.5.34 #​19268
  • Bump com.fasterxml.jackson:jackson-bom from 2.21.2 to 2.21.3 #​19133
  • Bump com.fasterxml.jackson:jackson-bom from 2.21.3 to 2.22.0 #​19246
  • Bump com.google.code.gson:gson from 2.13.2 to 2.14.0 #​19125
  • Bump com.nimbusds:oauth2-oidc-sdk from 11.37 to 11.37.1 #​19157
  • Bump com.nimbusds:oauth2-oidc-sdk from 11.37 to 11.37.2 #​19195
  • Bump com.webauthn4j:webauthn4j-core from 0.31.3.RELEASE to 0.31.5.RELEASE #​19148
  • Bump com.webauthn4j:webauthn4j-core from 0.31.5.RELEASE to 0.31.6.RELEASE #​19263
  • Bump gradle-wrapper from 9.4.1 to 9.5.0 #​19135
  • Bump gradle-wrapper from 9.5.0 to 9.5.1 #​19171
  • Bump io-micrometer from 1.16.5 to 1.17.0 #​19287
  • Bump io.mockk:mockk from 1.14.9 to 1.14.11 #​19244
  • Bump io.projectreactor:reactor-bom from 2025.0.5 to 2025.0.6 #​19296
  • Bump org-jetbrains-kotlin from 2.3.20 to 2.3.21 #​19126
  • Bump org-jetbrains-kotlin from 2.3.21 to 2.4.0 #​19264
  • Bump org-opensaml5 from 5.2.1 to 5.2.2 #​19176
  • Bump org.apache.maven:maven-resolver-provider from 3.9.15 to 3.9.16 #​19190
  • Bump org.apereo.cas.client:cas-client-core from 4.1.0 to 4.1.1 #​19200
  • Bump org.hibernate.orm:hibernate-core from 7.3.1.Final to 7.3.2.Final #​19119
  • Bump org.hibernate.orm:hibernate-core from 7.3.2.Final to 7.3.3.Final #​19149
  • Bump org.hibernate.orm:hibernate-core from 7.3.3.Final to 7.3.4.Final #​19165
  • Bump org.hibernate.orm:hibernate-core from 7.3.4.Final to 7.3.5.Final #​19191
  • Bump org.hibernate.orm:hibernate-core from 7.3.5.Final to 7.3.6.Final #​19211
  • Bump org.hibernate.orm:hibernate-core from 7.3.6.Final to 7.4.0.Final #​19226
  • Bump org.jetbrains.kotlinx:kotlinx-coroutines-bom from 1.10.2 to 1.11.0 #​19166
  • Bump org.junit:junit-bom from 6.0.3 to 6.1.0 #​19197
  • Bump org.slf4j:slf4j-api from 2.0.17 to 2.0.18 #​19169
  • Bump org.springframework.data:spring-data-bom from 2025.1.5 to 2025.1.6 #​19290
  • Bump org.springframework.ldap:spring-ldap-core from 4.0.3 to 4.1.0 #​19291
  • Bump org.springframework:spring-framework-bom from 7.0.7 to 7.0.8 #​19285
  • Bump spring-io/spring-release-actions from 0.0.4 to 0.0.5 #​19179
  • Bump tools.jackson:jackson-bom from 3.1.2 to 3.1.3 #​19147
  • Bump tools.jackson:jackson-bom from 3.1.3 to 3.1.4 #​19245
  • Bump tools.jackson:jackson-bom from 3.1.4 to 3.2.0 #​19286
  • Update to spring-data-bom 2026.0.0 #​19303
🔩 Build Updates

v7.0.6

Compare Source

🪲 Bug Fixes
  • FormPostRedirectStrategy should not emit percent-encoded values into hidden form inputs #​19137
  • AbstractAuthenticationFilterConfigurer should not automatically pick up servlet path #​19128
  • Principal Extractor should select the left-most RDN attribute value #​19254
🔨 Dependency Upgrades
  • Bump antora from 3.2.0-alpha.11 to 3.2.0-alpha.12 in /docs #​19184
  • Bump ch.qos.logback:logback-classic from 1.5.32 to 1.5.34 #​19266
  • Bump com.webauthn4j:webauthn4j-core from 0.31.3.RELEASE to 0.31.5.RELEASE #​19151
  • Bump com.webauthn4j:webauthn4j-core from 0.31.5.RELEASE to 0.31.6.RELEASE #​19265
  • Bump gradle-wrapper from 8.14.4 to 8.14.5 #​19160
  • Bump io-micrometer from 1.16.5 to 1.16.6 #​19292
  • Bump io.mockk:mockk from 1.14.9 to 1.14.11 #​19247
  • Bump io.projectreactor:reactor-bom from 2025.0.5 to 2025.0.6 #​19298
  • Bump org-bouncycastle from 1.80 to 1.80.2 #​19193
  • Bump org.apache.maven:maven-resolver-provider from 3.9.15 to 3.9.16 #​19192
  • Bump org.slf4j:slf4j-api from 2.0.17 to 2.0.18 #​19174
  • Bump org.springframework.data:spring-data-bom from 2025.1.5 to 2025.1.6 #​19294
  • Bump org.springframework.ldap:spring-ldap-core from 4.0.3 to 4.0.4 #​19289
  • Bump org.springframework:spring-framework-bom from 7.0.7 to 7.0.8 #​19288
  • Bump spring-io/spring-release-actions from 0.0.4 to 0.0.5 #​19182
  • Update to Micrometer 1.16.5 #​19225
🔩 Build Updates

v7.0.5

Compare Source

⭐ New Features

  • Add XML Based shouldWriteHeadersEagerly tests #​19018
  • Merge Add CredentialRecordOwnerAuthorizationManager #​19005

🪲 Bug Fixes

  • Add equals and hashcode to HttpMethodRequestMatcher #​18963
  • auth_time claim doesn't show the time of the original authentication #​18282
  • auth_time validation fails when SSO session is renewed #​18978
  • Fallback defaultTargetUrl if refererHeader is empty #​18981
  • Fix HttpSessionRequestCache#getMatchingRequest query string parsing #​18972
  • Merge Handle null value in OnCommittedResponseWrapper header methods #​18990
  • OAuth2 client sessionManagement ineffective with DefaultOidcUser #​19022

🔨 Dependency Upgrades

  • Bump @springio/antora-extensions from 1.14.10 to 1.14.11 in /docs #​19054
  • Bump @springio/antora-extensions from 1.14.7 to 1.14.9 in /docs #​18953
  • Bump @springio/antora-extensions from 1.14.9 to 1.14.10 in /docs #​19029
  • Bump @springio/asciidoctor-extensions from 1.0.0-alpha.17 to 1.0.0-alpha.18 in /docs #​18957
  • Bump actions/upload-artifact from 7.0.0 to 7.0.1 #​19096
  • Bump com.webauthn4j:webauthn4j-core from 0.31.1.RELEASE to 0.31.2.RELEASE #​19021
  • Bump com.webauthn4j:webauthn4j-core from 0.31.2.RELEASE to 0.31.3.RELEASE #​19114
  • Bump io.projectreactor:reactor-bom from 2025.0.4 to 2025.0.5 #​19080
  • Bump org.apache.maven:maven-resolver-provider from 3.9.14 to 3.9.15 #​19111
  • Bump org.springframework.data:spring-data-bom from 2025.1.4 to 2025.1.5 #​19113
  • Bump org.springframework.ldap:spring-ldap-core from 4.0.2 to 4.0.3 #​19098
  • Bump org.springframework:spring-framework-bom from 7.0.6 to 7.0.7 #​19112
  • Bump spring-io/spring-gradle-build-action from 2.0.5 to 2.0.6 #​18996
  • Bump spring-io/spring-release-actions from 0.0.3 to 0.0.4 #​19095
  • Bump spring-io/spring-security-release-tools/.github/workflows/update-scheduled-release-version.yml from 1.0.14 to 1.0.15 #​18948

❤️ Contributors

Thank you to all the contributors who worked on this release:

@​rwinch

v7.0.4

Compare Source

⭐ New Features

  • Update RestTemplateBuilder usage in opaque-token.adoc #​18836

🪲 Bug Fixes

  • Fix GrantedAuthority.authority null in AuthoritiesAuthorizationManager #​18784
  • Add Jackson Mixin for WebAuthnAuthentication #​18878
  • Add Missing OnCommitedResponseWrapper Header Overrides #​18799
  • Document the change in dependency coordinates with Spring Security 7 #​18773
  • Ensure tests clear AuthorizationServerContextHolder #​18768
  • Fix CookieRequestCache parameters #​18864
  • Fix Flaky Crypto Tests #​18842
  • Fix Jackson Deserializer for AuthenticationExtensionsClientOutputs #​18897
  • HttpMessageConverterAuthenticationSuccessHandler Supports Jackson 3 #​18834
  • OAuth2DeviceVerificationEndpointFilter should be applied after AuthorizationFilter #​18873
  • Restore upgradeEncoding condition in DaoAuthenticationProvider #​18788
  • saveAuthenticationRequest should read relayState from authenticationRequest #​18884
  • SecurityExpressionRoot#hasAuthority should delegate to AuthorizationManagerFactory#hasAuthority #​18487
  • ServerHttpSecurityConfiguration should not set userDetailsPasswordService to a null value #​18276
  • TokenBasedRememberMeServices documentation snippets should compile #​18642
  • Update request-matcher XML property to support PathPatternRequestMatcher #​18737

🔨 Dependency Upgrades

  • Bump @antora/collector-extension from 1.0.2 to 1.0.3 in /docs #​18853
  • Bump actions/upload-artifact from 6.0.0 to 7.0.0 #​18810
  • Bump ch.qos.logback:logback-classic from 1.5.29 to 1.5.32 #​18752
  • Bump com.webauthn4j:webauthn4j-core from 0.31.0.RELEASE to 0.31.1.RELEASE #​18830
  • Bump io.projectreactor:reactor-bom from 2025.0.3 to 2025.0.4 #​18877
  • Bump org-apache-maven-resolver from 1.9.25 to 1.9.26 #​18751
  • Bump org-apache-maven-resolver from 1.9.26 to 1.9.27 #​18792
  • Bump org.apache.maven:maven-resolver-provider from 3.9.12 to 3.9.13 #​18861
  • Bump org.apache.maven:maven-resolver-provider from 3.9.13 to 3.9.14 #​18887
  • Bump org.junit:junit-bom from 6.0.2 to 6.0.3 #​18743
  • Bump org.springframework.data:spring-data-bom from 2025.1.3 to 2025.1.4 #​18904
  • Bump org.springframework:spring-framework-bom from 7.0.4 to 7.0.5 #​18764
  • Bump org.springframework:spring-framework-bom from 7.0.5 to 7.0.6 #​18905
  • Update Antora UI Spring to v0.4.26 #​18893
  • Update to spring-security-release-tools 1.0.15 #​18909

❤️ Contributors

Thank you to all the contributors who worked on this release:

@​busoco-sjb, @​making, @​meliezer, @​ngocnhan-tran1996, @​rwinch, @​sephiroth-j, @​therepanic, @​thuri, and @​ziqin

v7.0.3

Compare Source

⭐ New Features

  • Fix Javadoc warnings in spring-security-web #​18473
  • Fix/gradle 9 deprecations #​18485
  • Fix/gradle 9 deprecations #​18477
  • Replace method call with 'Builder.configureMessageConverters()' #​18378
  • Replacing use of deprecated 'check' in authorization documentation #​18390
  • Use DefaultParameterNameDiscoverer#getSharedInstance #​18481

🪲 Bug Fixes

  • Authorization Server fails to start with multiple PasswordEncoder beans #​18645
  • BearerTokenAuthenticationEntryPoint uses context path #​18528
  • Create SHA-1 MessageDigest for every new check request in Compromised Password Checker #​18594
  • Document Client PKCE settings #​18304
  • Fix docs typo X-Requested-By -> X-Requested-With #​18123
  • Fix Formatting in mfa.adoc #​18134
  • Fix typo in documentation #​18344
  • Fix typos #​18121

🔨 Dependency Upgrades

  • Bump ch.qos.logback:logback-classic from 1.5.22 to 1.5.24 #​18384
  • Bump ch.qos.logback:logback-classic from 1.5.24 to 1.5.28 #​18684
  • Bump ch.qos.logback:logback-classic from 1.5.28 to 1.5.29 #​18711
  • Bump com.fasterxml.jackson:jackson-bom from 2.20.1 to 2.20.2 #​18660
  • Bump com.webauthn4j:webauthn4j-core from 0.29.7.RELEASE to 0.31.0.RELEASE #​18687
  • Bump gradle-wrapper from 8.14 to 8.14.4 #​18705
  • Bump io.mockk:mockk from 1.14.7 to 1.14.9 #​18681
  • Bump io.projectreactor:reactor-bom from 2025.0.1 to 2025.0.2 #​18658
  • Bump io.projectreactor:reactor-bom from 2025.0.2 to 2025.0.3 #​18717
  • Bump io.spring.develocity.conventions from 0.0.24 to 0.0.25 #​18683
  • Bump io.spring.gradle:spring-security-release-plugin from 1.0.13 to 1.0.14 #​18725
  • Bump jakarta.xml.bind:jakarta.xml.bind-api from 4.0.4 to 4.0.5 #​18706
  • Bump org-apache-maven-resolver from 1.9.24 to 1.9.25 #​18309
  • Bump org-aspectj from 1.9.25 to 1.9.25.1 #​18326
  • Bump org.apache.httpcomponents.client5:httpclient5 from 5.5.1 to 5.5.2 #​18346
  • Bump org.apache.maven:maven-resolver-provider from 3.9.11 to 3.9.12 #​18327
  • Bump org.assertj:assertj-core from 3.27.6 to 3.27.7 #​18682
  • Bump org.junit:junit-bom from 6.0.1 to 6.0.2 #​18385
  • Bump org.springframework.data:spring-data-bom from 2025.1.1 to 2025.1.2 #​18655
  • Bump org.springframework.ldap:spring-ldap-core from 4.0.0 to 4.0.1 #​18316
  • Bump org.springframework.ldap:spring-ldap-core from 4.0.1 to 4.0.2 #​18733
  • Bump org.springframework:spring-framework-bom from 7.0.3 to 7.0.4 #​18732
  • Bump org.springframework:spring-framework-bom from 7.0.3-SNAPSHOT to 7.0.4-SNAPSHOT #​18657
  • Bump spring-io/spring-doc-actions from 0.0.20 to 0.0.22 #​18651
  • Bump tools.jackson:jackson-bom from 3.0.3 to 3.0.4 #​18659
  • Update Antora UI Spring to v0.4.25 #​18249
  • Update to Spring Framework 7.0.3 #​18667
  • Update to spring-data-bom 2025.1.3 #​18735

❤️ Contributors

Thank you to all the contributors who worked on this release:

@​Been24, @​Fr05ty-hub, @​Kehrlann, @​Rigu1, @​bloomsei, @​martinboulais, @​ngocnhan-tran1996, @​paulvas, @​rwinch, @​therepanic, and @​vincentstradiot

v7.0.2

Compare Source

🪲 Bug Fixes

  • AuthorizationWebProxyConfiguration should only be active when both spring-security-web and spring-webmvc are on the classpath #​18315

v7.0.1

Compare Source

⭐ New Features

  • Stop deploying JavaDoc outside of Antora #​18200

🪲 Bug Fixes

  • An unexpected dependency appeared for spring-security-config of spring-security-web #​18307
  • Fix "typ" header value in NimbusJwtEncoder-encoded JWT #​18270
  • Fix broken link to Spring Boot docs #​18236
  • Fix documentation resource server sample title #​18231
  • Fix MyCustomDsl to use csrf(Customizer) instead of removed csrf().disabled() #​18223
  • Fix typo in AnnotationTemplateExpressionDefaults documentation #​18255
  • Fix typos in documentation depenendencies->dependencies #​18209
  • NimbusJwtEncoder produces JWT with wrong "typ" header value #​18269
  • OAuth2AuthorizationEndpointFilter should be applied after AuthorizationFilter #​18251
  • Remove requireProofKey warning for non-auth-code flows #​18221
  • Remove throws from MyCustomDsl in docs #​18224

🔨 Dependency Upgrades

  • Bump ch.qos.logback:logback-classic from 1.5.20 to 1.5.21 #​18214
  • Bump ch.qos.logback:logback-classic from 1.5.21 to 1.5.22 #​18311
  • Bump com.fasterxml.jackson:jackson-bom from 2.20.0 to 2.20.1 #​18245
  • Bump com.unboundid:unboundid-ldapsdk from 7.0.3 to 7.0.4 #​18262
  • Bump io.micrometer:micrometer-observation from 1.14.12 to 1.14.13 #​18189
  • Bump io.micrometer:micrometer-observation from 1.14.13 to 1.14.14 #​18277
  • Bump io.mockk:mockk from 1.14.6 to 1.14.7 #​18274
  • Bump io.projectreactor:reactor-bom from 2025.0.0 to 2025.0.1 #​18289
  • Bump io.spring.gradle:spring-security-release-plugin from 1.0.10 to 1.0.13 #​18187
  • Bump org-aspectj from 1.9.24 to 1.9.25 #​18186
  • Bump org.apache.kerby:kerb-simplekdc from 2.1.0 to 2.1.1 #​18215
  • Bump org.junit:junit-bom from 6.0.0 to 6.0.1 #​18188
  • Bump org.springframework.data:spring-data-bom from 2025.1.0 to 2025.1.1 #​18312
  • Bump org.springframework:spring-framework-bom from 7.0.0 to 7.0.1 #​18213
  • Bump org.springframework:spring-framework-bom from 7.0.1 to 7.0.2 #​18310
  • Bump tools.jackson:jackson-bom from 3.0.1 to 3.0.2 #​18212
  • Bump tools.jackson:jackson-bom from 3.0.2 to 3.0.3 #​18244

🔩 Build Updates

  • Add Test for ServletRequestPathUtils.parseAndCache(method=null) #​18166
  • Bump antora from 3.2.0-alpha.10 to 3.2.0-alpha.11 in /docs #​18238

❤️ Contributors

Thank you to all the contributors who worked on this release:

@​L33gn21, @​ghusta, @​ronodhirSoumik, @​rwinch, @​sach429, and @​ziqin

v7.0.0

Compare Source

⭐ New Features

  • Add a minimal authorization server configuration #​18153
  • Mark GrantedAuthority#getAuthority as @Nullable #​18014
  • Polish SimpleGrantedAuthority #​18062

🪲 Bug Fixes

  • Correct the org.springframework.security.config.annotation.web.LogoutDsl's property description #​18026
  • Fix webauthn multifactor authentication #​18163

🔨 Dependency Upgrades

  • Bump org.jetbrains.kotlin:kotlin-bom from 2.2.20 to 2.2.21 #​18099
  • Bump org.jetbrains.kotlin:kotlin-gradle-plugin from 2.2.20 to 2.2.21 #​18100
  • Bump tools.jackson:jackson-bom from 3.0.0 to 3.0.1 #​18097
  • Update to Reactor 2025.0.0 #​18173
  • Update to Spring Data 2025.1.0 #​18174
  • Update to Spring Framework 7.0.0 #​18172
  • Update to Spring LDAP 4.0.0 #​18175

❤️ Contributors

Thank you to all the contributors who worked on this release:

@​Kehrlann, @​SimonVonXCVII, @​quaff, and @​therepanic

v6.5.11

Compare Source

🪲 Bug Fixes

  • FormPostRedirectStrategy should not emit percent-encoded values into hidden form inputs #​19136

🔨 Dependency Upgrades

  • Bump antora from 3.2.0-alpha.11 to 3.2.0-alpha.12 in /docs #​19185
  • Bump ch.qos.logback:logback-classic from 1.5.32 to 1.5.34 #​19299
  • Bump com.fasterxml.jackson:jackson-bom from 2.18.6 to 2.18.7 #​19129
  • Bump com.fasterxml.jackson:jackson-bom from 2.18.7 to 2.18.8 #​19297
  • Bump gradle-wrapper from 8.14.4 to 8.14.5 #​19159
  • Bump org-bouncycastle from 1.80 to 1.80.2 #​19204
  • Bump org.apache.maven:maven-resolver-provider from 3.9.15 to 3.9.16 #​19205
  • Bump org.hibernate.orm:hibernate-core from 6.6.49.Final to 6.6.50.Final #​19150
  • Bump org.hibernate.orm:hibernate-core from 6.6.50.Final to 6.6.51.Final #​19213
  • Bump org.hibernate.orm:hibernate-core from 6.6.51.Final to 6.6.53.Final #​19300
  • Bump org.slf4j:slf4j-api from 2.0.17 to 2.0.18 #​19173
  • Bump org.springframework:spring-framework-bom from 6.2.18 to 6.2.19 #​19293
  • Bump spring-io/spring-gradle-build-action from 2.0.5 to 2.0.6 #​19124
  • Bump spring-io/spring-release-actions from 0.0.4 to 0.0.5 #​19183
  • Update micrometer-bom to 1.15.12 #​19302
  • Update to Micrometer 1.15.11 #​19224
  • Update to reactor-bom 2024.0.18 #​19301

🔩 Build Updates

v6.5.10

Compare Source

⭐ New Features

  • Add CredentialRecordOwnerAuthorizationManager #​19004
  • Add XML Based shouldWriteHeadersEagerly tests #​19017
  • Clarify Session Management Persistence Documentation #​18345
  • Update FilterChainProxy#getFilters(String) javadoc #​18258

🪲 Bug Fixes

  • Add equals and hashcode to HttpMethodRequestMatcher #​18914
  • auth_time validation fails when SSO session is renewed #​18839
  • Fallback defaultTargetUrl if refererHeader is empty #​18806
  • Fix HttpSessionRequestCache#getMatchingRequest query string parsing #​16914
  • Fix documentation for Custom Authorization Manager #​18362
  • Improve serialVersionUID check in tests #​18474
  • Merge Handle null value in OnCommittedResponseWrapper header methods #​18989
  • OAuth2 client sessionManagement ineffective with DefaultOidcUser #​18622

🔨 Dependency Upgrades

  • Bump @springio/antora-extensions from 1.14.10 to 1.14.11 in /docs #​19055
  • Bump @springio/antora-extensions from 1.14.7 to 1.14.9 in /docs #​18956
  • Bump @springio/antora-extensions from 1.14.9 to 1.14.10 in /docs #​19031
  • Bump @springio/asciidoctor-extensions from 1.0.0-alpha.17 to 1.0.0-alpha.18 in /docs #​18952
  • Bump actions/upload-artifact from 7.0.0 to 7.0.1 #​19094
  • Bump io.projectreactor:reactor-bom from 2024.0.16 to 2024.0.17 #​19078
  • Bump io.spring.gradle:spring-security-release-plugin from 1.0.14 to 1.0.15 #​18916
  • Bump org.apache.maven:maven-resolver-provider from 3.9.14 to 3.9.15 #​19108
  • Bump org.hibernate.orm:hibernate-core from 6.6.44.Final to 6.6.45.Final #​18966
  • Bump org.hibernate.orm:hibernate-core from 6.6.45.Final to 6.6.47.Final #​19046
  • Bump org.hibernate.orm:hibernate-core from 6.6.47.Final to 6.6.48.Final #​19064
  • Bump org.hibernate.orm:hibernate-core from 6.6.48.Final to 6.6.49.Final #​19110
  • Bump org.springframework:spring-framework-bom from 6.2.17 to 6.2.18 #​19109
  • Bump spring-io/spring-release-actions from 0.0.3 to 0.0.4 #​19093
  • Bump spring-io/spring-security-release-tools from 1.0.14 to 1.0.15 #​18954
  • Bump spring-io/spring-security-release-tools/.github/workflows/build.yml from 1.0.14 to 1.0.15 #​18955
  • Bump spring-io/spring-security-release-tools/.github/workflows/deploy-artifacts.yml from 1.0.14 to 1.0.15 #​18949
  • Bump spring-io/spring-security-release-tools/.github/workflows/deploy-schema.yml from 1.0.14 to 1.0.15 #​18950
  • Bump spring-io/spring-security-release-tools/.github/workflows/perform-release.yml from 1.0.14 to 1.0.15 #​18995
  • Bump spring-io/spring-security-release-tools/.github/workflows/test.yml from 1.0.14 to 1.0.15 #​18951
  • Bump spring-io/spring-security-release-tools/.github/workflows/update-scheduled-release-version.yml from 1.0.14 to 1.0.15 #​18994
  • Update to spring-security-release-tools 1.0.15 #​18910

❤️ Contributors

Thank you to all the contributors who worked on this release:

@​Kehrlann, @​as1605, @​johnycho, @​ngocnhan-tran1996, @​rwinch, and @​sankranty

v6.5.9

Compare Source

⭐ New Features

🪲 Bug Fixes

  • Fix GrantedAuthority.authority null in AuthoritiesAuthorizationManager #​18544
  • saveAuthenticationRequest should read relayState from authenticationRequest #​18872
  • Add Missing OnCommitedResponseWrapper Header Overrides #​18798
  • Clarify Resource Server startup expectations #​18518
  • Correct Reference to Clear-Site-Data Directive enum #​18273
  • Fix CookieRequestCache parameters #​18857
  • Fix Flaky Crypto Tests #​18841
  • Fix Jackson Deserializer for AuthenticationExtensionsClientOutputs #​18896

🔨 Dependency Upgrades

  • Bump @antora/collector-extension from 1.0.2 to 1.0.3 in /docs #​18854
  • Bump actions/upload-artifact from 6.0.0 to 7.0.0 #​18809
  • Bump ch.qos.logback:logback-classic from 1.5.29 to 1.5.32 #​18749
  • Bump com.fasterxml.jackson:jackson-bom from 2.18.5 to 2.18.6 #​18779
  • Bump io.projectreactor:reactor-bom from 2024.0.15 to 2024.0.16 #​18876
  • Bump org-apache-maven-resolver from 1.9.25 to 1.9.26 #​18750
  • Bump org-apache-maven-resolver from 1.9.26 to 1.9.27 #​18791
  • Bump org.apache.maven:maven-resolver-provider from 3.9.12 to 3.9.13 #​18860
  • Bump org.apache.maven:maven-resolver-provider from 3.9.13 to 3.9.14 #​18886
  • Bump org.hibernate.orm:hibernate-core from 6.6.42.Final to 6.6.43.Final #​18780
  • Bump org.hibernate.orm:hibernate-core from 6.6.43.Final to 6.6.44.Final #​18829
  • Bump org.springframework:spring-framework-bom from 6.2.16 to 6.2.17 #​18903

❤️ Contributors

Thank you to all the contributors who worked on this release:

@​Hann244, @​Khyojae, @​ghusta, @​itsmevichu, @​qihaiyan, @​rwinch, @​therepanic, and @​ziqin

v6.5.8

Compare Source

⭐ New Feature

Note

PR body was truncated to here.


Configuration

📅 Schedule: (in timezone Europe/London)

  • Branch creation
    • "after 7am and before 11am every weekday"
  • Automerge
    • At any time (no schedule defined)

🚦 Automerge: Disabled by config. Please merge this manually once you are satisfied.

Rebasing: Whenever PR is behind base branch, or you tick the rebase/retry checkbox.

🔕 Ignore: Close this PR and you won't be reminded about these updates again.


  • If you want to rebase/retry this PR, check this box

This PR was generated by Mend Renovate. View the repository job log.

@renovate renovate Bot added the dependencies Pull requests that update a dependency file label Apr 7, 2026
@renovate
renovate Bot force-pushed the renovate/major-spring-security branch 8 times, most recently from d41db2f to 395dd90 Compare April 13, 2026 15:48
@renovate
renovate Bot force-pushed the renovate/major-spring-security branch 3 times, most recently from 3970c92 to 79cf5da Compare April 22, 2026 11:09
@renovate
renovate Bot force-pushed the renovate/major-spring-security branch from 79cf5da to 1d1db8a Compare April 29, 2026 19:01
@renovate renovate Bot changed the title Update spring security to v7 (major) Update spring security to v7 May 15, 2026
@renovate
renovate Bot force-pushed the renovate/major-spring-security branch 6 times, most recently from 703bb55 to 8bab5bf Compare June 15, 2026 10:54
@renovate
renovate Bot force-pushed the renovate/major-spring-security branch 2 times, most recently from 534b0f5 to 9cea18b Compare July 2, 2026 09:56
@renovate
renovate Bot force-pushed the renovate/major-spring-security branch 3 times, most recently from 657b6a0 to 64cb0c4 Compare July 9, 2026 11:53
@renovate
renovate Bot force-pushed the renovate/major-spring-security branch 5 times, most recently from ba9a841 to ddd5180 Compare July 16, 2026 16:38
@renovate
renovate Bot force-pushed the renovate/major-spring-security branch 6 times, most recently from b5d737a to 4d62bd5 Compare July 22, 2026 11:30
@renovate
renovate Bot force-pushed the renovate/major-spring-security branch from 4d62bd5 to 6af2c15 Compare July 27, 2026 09:47
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

dependencies Pull requests that update a dependency file

Projects

None yet

Development

Successfully merging this pull request may close these issues.

0 participants