Skip to content

Bump spring-security-config from 4.2.20.RELEASE to 5.5.2#2164

Closed
dependabot[bot] wants to merge 1 commit into
masterfrom
dependabot/gradle/org.springframework.security-spring-security-config-5.5.2
Closed

Bump spring-security-config from 4.2.20.RELEASE to 5.5.2#2164
dependabot[bot] wants to merge 1 commit into
masterfrom
dependabot/gradle/org.springframework.security-spring-security-config-5.5.2

Conversation

@dependabot
Copy link
Copy Markdown

@dependabot dependabot Bot commented on behalf of github Aug 17, 2021

Bumps spring-security-config from 4.2.20.RELEASE to 5.5.2.

Release notes

Sourced from spring-security-config's releases.

5.5.2

⭐ New Features

  • Consider adding springFrameworkVersion property #10068
  • Introduce samplesBranch property #10036
  • Use the new springFrameworkVersion property in docs' links #10067

🔨 Dependency Upgrades

  • Update com.nimbusds to 9.9.1 #10186
  • Update io.projectreactor to 2020.0.10 #10187
  • Update jackson-bom to 2.12.4 #10183
  • Update jackson-databind to 2.12.4 #10184
  • Update jackson-datatype-jsr310 to 2.12.4 #10185
  • Update logback-classic to 1.2.5 #10182
  • Update org.aspectj to 1.9.7 #10189
  • Update org.eclipse.jetty to 9.4.43.v20210629 #10190
  • Update org.jetbrains.kotlin to 1.5.21 #10191
  • Update org.jetbrains.kotlinx to 1.5.1 #10192
  • Update org.slf4j to 1.7.32 #10193
  • Update org.springframework to 5.3.9 #10194
  • Update org.springframework.data to 2021.0.4 #10195
  • Update reactor-netty to 1.0.10 #10188

5.5.1

⭐ New Features

  • Consider adding a link checker to build #9972
  • Use Job Outputs to Transmit Error #9928
  • Store one request by default in WebSessionOAuth2ServerAuthorizationRequestRepository #9917
  • Combine different OS Build in one CI Job #9798
  • Use GPG_PRIVATE_KEY directly #9778

🪲 Bug Fixes

  • Update links to point to migrated samples #9971
  • Add messaging to documentation about sample migration #9970
  • Fix broken links in docs #9969
  • CORS section is missing in Reactive reference documentation #9952
  • RSocket documentation mentions non-existent class #9950
  • Disabling logout keeps LogoutPageGeneratingWebFilter registered at /logout #9941
  • Missing log of "caused by" exception when OP document metadata cannot be reached #9939
  • Missing support for private_key_jwt in ClientRegistrations #9936
  • Allow client registration from issuer uri with no authorize_endpoint #9935
  • Missing support for urn:ietf:params:oauth:grant-type:jwt-bearer in ClientRegistrations #9934
  • Using the SecurityMockServerConfigurers.java requires the com.nimbusds oauth2-oidc-sdk on the classpath #9929
  • Jwt client authentication converter should detect new key #9927
  • Adding filters relative to custom ones is broken #9906
  • SEC-3139: Anonymous authentication token not passed to Controller #9890
  • Clarify quick start section in README #9885

... (truncated)

Changelog

Sourced from spring-security-config's changelog.

= Update Dependencies

Ensure you have no changes in your local repository. Change to a new branch. For example:

[source,bash]

$ git checkout -b 5.5.0-RC1-dependencies

Review the rules in build.gradle to ensure the rules make sense. For example, we should not allow major version updates in a patch release. Also ensure that all of the exclusions still make sense.

The following Gradle command will update your dependencies creating a commit for each dependency update. The first invocation of the command will take quite a while (~20 minutes depending on internet speed) to run because it is indexing all the versions of all the dependencies.

[source,bash]

$ ./gradlew updateDependencies

Review the commits to ensure that the updated dependency versions make sense for this release. For example, we should not perform a major version update for a patch release.

[source,bash]

$ git log

If any of the versions don’t make sense, update build.gradle to ensure that the version is excluded.

Run all the checks:

[source,bash]

$ ./gradlew check

If they don’t work, you can run a git bisect to discover what broke the build. Fix any commits that broke the build.

Check out the original brach:

[source,bash]

$ git checkout -

The following command will update the dependencies again but this time creating a ticket for each update and placing Closes gh-<number> in the commit. Replacing the following values:

... (truncated)

Commits
  • bdc3fea Release 5.5.2
  • 134f8b0 Update org.springframework.data to 2021.0.4
  • 835ee55 Update org.springframework to 5.3.9
  • cfe4855 Update org.slf4j to 1.7.32
  • c7b73d7 Update org.jetbrains.kotlinx to 1.5.1
  • 618edc2 Update org.jetbrains.kotlin to 1.5.21
  • f7fef10 Update org.eclipse.jetty to 9.4.43.v20210629
  • 9be97e7 Update org.aspectj to 1.9.7
  • 603e0a4 Update io.projectreactor to 2020.0.10
  • b081627 Update com.nimbusds to 9.9.1
  • Additional commits viewable in compare view

Dependabot compatibility score

Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting @dependabot rebase.


Dependabot commands and options

You can trigger Dependabot actions by commenting on this PR:

  • @dependabot rebase will rebase this PR
  • @dependabot recreate will recreate this PR, overwriting any edits that have been made to it
  • @dependabot merge will merge this PR after your CI passes on it
  • @dependabot squash and merge will squash and merge this PR after your CI passes on it
  • @dependabot cancel merge will cancel a previously requested merge and block automerging
  • @dependabot reopen will reopen this PR if it is closed
  • @dependabot close will close this PR and stop Dependabot recreating it. You can achieve the same result by closing it manually
  • @dependabot ignore this major version will close this PR and stop Dependabot creating any more for this major version (unless you reopen the PR or upgrade to it yourself)
  • @dependabot ignore this minor version will close this PR and stop Dependabot creating any more for this minor version (unless you reopen the PR or upgrade to it yourself)
  • @dependabot ignore this dependency will close this PR and stop Dependabot creating any more for this dependency (unless you reopen the PR or upgrade to it yourself)

Bumps [spring-security-config](https://github.com/spring-projects/spring-security) from 4.2.20.RELEASE to 5.5.2.
- [Release notes](https://github.com/spring-projects/spring-security/releases)
- [Changelog](https://github.com/spring-projects/spring-security/blob/main/RELEASE.adoc)
- [Commits](spring-projects/spring-security@4.2.20.RELEASE...5.5.2)

---
updated-dependencies:
- dependency-name: org.springframework.security:spring-security-config
  dependency-type: direct:production
  update-type: version-update:semver-major
...

Signed-off-by: dependabot[bot] <support@github.com>
@dependabot dependabot Bot added dependencies Pull requests that update a dependency file java Pull requests that update Java code labels Aug 17, 2021
@dependabot @github
Copy link
Copy Markdown
Author

dependabot Bot commented on behalf of github Oct 19, 2021

Superseded by #2273.

@dependabot dependabot Bot closed this Oct 19, 2021
@dependabot dependabot Bot deleted the dependabot/gradle/org.springframework.security-spring-security-config-5.5.2 branch October 19, 2021 18:16
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

dependencies Pull requests that update a dependency file java Pull requests that update Java code

Projects

None yet

Development

Successfully merging this pull request may close these issues.

0 participants