Skip to content

Build(deps): Bump the prod-deps-ver group across 1 directory with 22 updates - #2021

Closed
dependabot[bot] wants to merge 1 commit into
mainfrom
dependabot/maven/prod-deps-ver-6fecf740a5
Closed

dependabot[bot] wants to merge 1 commit into
mainfrom
dependabot/maven/prod-deps-ver-6fecf740a5

Conversation

@dependabot

@dependabot dependabot Bot commented on behalf of github Aug 24, 2026 •

Copy link
Copy Markdown
Contributor

Bumps the prod-deps-ver group with 22 updates in the / directory:

Package From To
org.junit:junit-bom 6.1.2 6.1.3
org.junit.jupiter:junit-jupiter-engine 6.1.2 6.1.3
org.junit.jupiter:junit-jupiter-params 6.1.2 6.1.3
org.junit.jupiter:junit-jupiter-api 6.1.2 6.1.3
org.eclipse.jetty:jetty-bom 12.1.11 12.1.12
org.eclipse.jetty.ee10:jetty-ee10-servlet 12.1.11 12.1.12
org.eclipse.jetty.ee10:jetty-ee10-webapp 12.1.11 12.1.12
org.springframework.security:spring-security-bom 7.1.0 7.1.1
org.springframework.security:spring-security-core 7.1.0 7.1.1
org.springframework.boot:spring-boot-dependencies 4.1.0 4.1.1
org.springframework.boot:spring-boot-starter-test 4.1.0 4.1.1
org.springframework.boot:spring-boot-autoconfigure 4.1.0 4.1.1
org.springframework.boot:spring-boot-starter-tomcat 4.1.0 4.1.1
org.springframework:spring-core 7.0.8 7.0.9
org.springframework:spring-web 7.0.8 7.0.9
org.springframework:spring-aop 7.0.8 7.0.9
org.springframework:spring-beans 7.0.8 7.0.9
org.springframework.security:spring-security-oauth2-client 7.1.0 7.1.1
com.github.spotbugs:spotbugs-annotations 4.10.3 4.10.4
io.projectreactor:reactor-core 3.8.2 3.8.7
io.projectreactor:reactor-test 3.8.2 3.8.7
com.github.spotbugs:spotbugs-maven-plugin 4.10.3.0 4.10.4.0

Updates org.junit:junit-bom from 6.1.2 to 6.1.3

Release notes

Sourced from org.junit:junit-bom's releases.

JUnit 6.1.3 = Platform 6.1.3 + Jupiter 6.1.3 + Vintage 6.1.3

See Release Notes.

Full Changelog: junit-team/junit-framework@r6.1.2...r6.1.3

Commits
  • f59f60d Release 6.1.3
  • cd8ec92 Finalize 6.1.3 release notes
  • c8729f2 Restore compatibility with GraalVM 25 (#5901)
  • ddc9e74 Update graalvm/setup-graalvm action to v1.6.4 (#5959)
  • fe2c52a Update plugin org.graalvm.buildtools.native to v1.1.7 (#5923)
  • 62afc02 Delay GraalVM plugin updates for 3 days
  • 0cc2902 Skip graalVmTest task if GraalVM env vars are not set
  • f6bbfc5 Move GraalVM tests to separate test task (#5903)
  • e87e052 Update plugin org.graalvm.buildtools.native to v1.1.6 (#5899)
  • 1cd56df Update plugin org.graalvm.buildtools.native to v1.1.5 (#5880)
  • Additional commits viewable in compare view

Updates org.junit.jupiter:junit-jupiter-engine from 6.1.2 to 6.1.3

Release notes

Sourced from org.junit.jupiter:junit-jupiter-engine's releases.

JUnit 6.1.3 = Platform 6.1.3 + Jupiter 6.1.3 + Vintage 6.1.3

See Release Notes.

Full Changelog: junit-team/junit-framework@r6.1.2...r6.1.3

Commits
  • f59f60d Release 6.1.3
  • cd8ec92 Finalize 6.1.3 release notes
  • c8729f2 Restore compatibility with GraalVM 25 (#5901)
  • ddc9e74 Update graalvm/setup-graalvm action to v1.6.4 (#5959)
  • fe2c52a Update plugin org.graalvm.buildtools.native to v1.1.7 (#5923)
  • 62afc02 Delay GraalVM plugin updates for 3 days
  • 0cc2902 Skip graalVmTest task if GraalVM env vars are not set
  • f6bbfc5 Move GraalVM tests to separate test task (#5903)
  • e87e052 Update plugin org.graalvm.buildtools.native to v1.1.6 (#5899)
  • 1cd56df Update plugin org.graalvm.buildtools.native to v1.1.5 (#5880)
  • Additional commits viewable in compare view

Updates org.junit.jupiter:junit-jupiter-params from 6.1.2 to 6.1.3

Release notes

Sourced from org.junit.jupiter:junit-jupiter-params's releases.

JUnit 6.1.3 = Platform 6.1.3 + Jupiter 6.1.3 + Vintage 6.1.3

See Release Notes.

Full Changelog: junit-team/junit-framework@r6.1.2...r6.1.3

Commits
  • f59f60d Release 6.1.3
  • cd8ec92 Finalize 6.1.3 release notes
  • c8729f2 Restore compatibility with GraalVM 25 (#5901)
  • ddc9e74 Update graalvm/setup-graalvm action to v1.6.4 (#5959)
  • fe2c52a Update plugin org.graalvm.buildtools.native to v1.1.7 (#5923)
  • 62afc02 Delay GraalVM plugin updates for 3 days
  • 0cc2902 Skip graalVmTest task if GraalVM env vars are not set
  • f6bbfc5 Move GraalVM tests to separate test task (#5903)
  • e87e052 Update plugin org.graalvm.buildtools.native to v1.1.6 (#5899)
  • 1cd56df Update plugin org.graalvm.buildtools.native to v1.1.5 (#5880)
  • Additional commits viewable in compare view

Updates org.junit.jupiter:junit-jupiter-api from 6.1.2 to 6.1.3

Release notes

Sourced from org.junit.jupiter:junit-jupiter-api's releases.

JUnit 6.1.3 = Platform 6.1.3 + Jupiter 6.1.3 + Vintage 6.1.3

See Release Notes.

Full Changelog: junit-team/junit-framework@r6.1.2...r6.1.3

Commits
  • f59f60d Release 6.1.3
  • cd8ec92 Finalize 6.1.3 release notes
  • c8729f2 Restore compatibility with GraalVM 25 (#5901)
  • ddc9e74 Update graalvm/setup-graalvm action to v1.6.4 (#5959)
  • fe2c52a Update plugin org.graalvm.buildtools.native to v1.1.7 (#5923)
  • 62afc02 Delay GraalVM plugin updates for 3 days
  • 0cc2902 Skip graalVmTest task if GraalVM env vars are not set
  • f6bbfc5 Move GraalVM tests to separate test task (#5903)
  • e87e052 Update plugin org.graalvm.buildtools.native to v1.1.6 (#5899)
  • 1cd56df Update plugin org.graalvm.buildtools.native to v1.1.5 (#5880)
  • Additional commits viewable in compare view

Updates org.eclipse.jetty:jetty-bom from 12.1.11 to 12.1.12

Release notes

Sourced from org.eclipse.jetty:jetty-bom's releases.

12.1.12

Special Thanks to the following Eclipse Jetty community members

Changelog

  • #15496 - mime-type filtering by IncludeExclude should always be case-insensitive
  • #15456 - Fragments in redirects not supported by default in standalone Jetty installation
  • #15453 - HttpServletResponse: setHeader("Content-Length", N) should be treated like setContentLengthLong(N)
  • #13970 - ForwardedRequestCustomizer uses connection port instead of proto default when host lacks port (@​zenios)
  • #577 - AbstractProxyServlet onServerResponseHeaders addHeader rather than setHeader
Commits
  • 10dd394 Updating to version 12.1.12
  • 13d3a5b back to 12.1.2-SNAPSHOT
  • 9463025 Updating to version 12.1.12
  • bee8be9 back to 12.1.2-SNAPSHOT
  • f7cf5ec requiredExecutable+ dot
  • c03a11a Updating to version 12.1.13-SNAPSHOT
  • 28a88bd Updating to version 12.1.12
  • 5699fb4 Fix regression of duplicate header via proxy (#15531)
  • 337ae3e [12.1.x Root pom] Bump the build-deps group across 1 directory with 2 updates...
  • a0158c2 [12.1.x EE9] Bump the build-deps group across 1 directory with 2 updates (#15...
  • Additional commits viewable in compare view

Updates org.eclipse.jetty.ee10:jetty-ee10-servlet from 12.1.11 to 12.1.12

Updates org.eclipse.jetty.ee10:jetty-ee10-webapp from 12.1.11 to 12.1.12

Updates org.springframework.security:spring-security-bom from 7.1.0 to 7.1.1

Release notes

Sourced from org.springframework.security:spring-security-bom's releases.

7.1.1

⭐ New Features

  • Fix Broken DefaultLoginPageGeneratingFilter Javadoc Link #19252
  • Remove BeanResolver Null Checks #19209
  • Remove Unnecessary AuthorizationDecision Cast #19283
  • Update One-Time Token Docs for Renamed APIs #19274

🪲 Bug Fixes

  • Correct validation logic in CasAuthenticationToken #19372
  • Differentiate Forwarded and X-Forwarded headers in proxy docs #19477
  • Find mixed-case names in InMemoryUserDetailsManager#changePassword #19539
  • Fix OAuth2PushedAuthorizationRequestUri parsing #19445
  • Update JavaDoc Links in Reference #19199
  • Validate Parameter in setPostAuthenticationChecks #19277

🔨 Dependency Upgrades

  • Bump @springio/antora-extensions from 1.14.12 to 1.14.13 in /docs #19503
  • Bump actions/checkout from 6.0.3 to 7.0.0 #19351
  • Bump actions/checkout from 7.0.0 to 7.0.1 #19464
  • Bump actions/setup-java from 5.2.0 to 5.3.0 #19352
  • Bump actions/setup-java from 5.3.0 to 5.4.0 #19380
  • Bump actions/setup-java from 5.4.0 to 5.5.0 #19430
  • Bump actions/setup-java from 5.5.0 to 5.6.0 #19453
  • Bump actions/setup-java from 5.6.0 to 5.7.0 #19501
  • Bump antora from 3.2.0-alpha.12 to 3.2.0-rc.2 in /docs #19385
  • Bump ch.qos.logback:logback-classic from 1.5.34 to 1.5.35 #19374
  • Bump ch.qos.logback:logback-classic from 1.5.35 to 1.5.36 #19389
  • Bump ch.qos.logback:logback-classic from 1.5.36 to 1.5.37 #19396
  • Bump ch.qos.logback:logback-classic from 1.5.37 to 1.5.38 #19431
  • Bump ch.qos.logback:logback-classic from 1.5.38 to 1.6.0 #19467
  • Bump ch.qos.logback:logback-classic from 1.6.0 to 1.6.1 #19476
  • Bump ch.qos.logback:logback-classic from 1.6.1 to 1.6.2 #19556
  • Bump ch.qos.logback:logback-classic from 1.6.2 to 1.6.3 #19564
  • Bump com.fasterxml.jackson:jackson-bom from 2.22.0 to 2.22.1 #19419
  • Bump com.fasterxml.jackson:jackson-bom from 2.22.1 to 2.22.2 #19566
  • Bump com.nimbusds:oauth2-oidc-sdk from 11.37.2 to 11.38.1 #19439
  • Bump com.nimbusds:oauth2-oidc-sdk from 11.38.1 to 11.38.2 #19525
  • Bump com.unboundid:unboundid-ldapsdk from 7.0.4 to 7.0.5 #19322
  • Bump com.webauthn4j:webauthn4j-core from 0.31.6.RELEASE to 0.31.7.RELEASE #19313
  • Bump com.webauthn4j:webauthn4j-core from 0.31.7.RELEASE to 0.31.8.RELEASE #19409
  • Bump com.webauthn4j:webauthn4j-core from 0.31.8.RELEASE to 0.31.9.RELEASE #19496
  • Bump gradle-wrapper from 9.5.1 to 9.6.0 #19360
  • Bump gradle-wrapper from 9.6.0 to 9.6.1 #19393
  • Bump gradle-wrapper from 9.6.1 to 9.7.0 #19516
  • Bump io.spring.nullability:io.spring.nullability.gradle.plugin from 0.0.13 to 0.0.14 #19378
  • Bump org-bouncycastle from 1.84 to 1.85 #19437
  • Bump org-jetbrains-kotlin from 2.4.0 to 2.4.10 #19447

... (truncated)

Commits
  • a825937 Release 7.1.1
  • 74c91f8 Update to Spring Data 2026.0.1
  • b822214 Update to Spring LDAP 4.1.1
  • 39da00f Update to Micrometer 1.17.1
  • 4be80b7 Update to Reactor 2025.0.7
  • 564a677 Update to Spring Framework 7.0.9
  • 2930198 Configure Build for Commercial Repositories
  • 25f9a91 Configure with Commercial Workflows
  • bf8569f Remove OSS CI configuration
  • dcee218 Use jspecify Nullable in DPoPProofReplayValidator
  • Additional commits viewable in compare view

Updates org.springframework.security:spring-security-core from 7.1.0 to 7.1.1

Release notes

Sourced from org.springframework.security:spring-security-core's releases.

7.1.1

⭐ New Features

  • Fix Broken DefaultLoginPageGeneratingFilter Javadoc Link #19252
  • Remove BeanResolver Null Checks #19209
  • Remove Unnecessary AuthorizationDecision Cast #19283
  • Update One-Time Token Docs for Renamed APIs #19274

🪲 Bug Fixes

  • Correct validation logic in CasAuthenticationToken #19372
  • Differentiate Forwarded and X-Forwarded headers in proxy docs #19477
  • Find mixed-case names in InMemoryUserDetailsManager#changePassword #19539
  • Fix OAuth2PushedAuthorizationRequestUri parsing #19445
  • Update JavaDoc Links in Reference #19199
  • Validate Parameter in setPostAuthenticationChecks #19277

🔨 Dependency Upgrades

  • Bump @springio/antora-extensions from 1.14.12 to 1.14.13 in /docs #19503
  • Bump actions/checkout from 6.0.3 to 7.0.0 #19351
  • Bump actions/checkout from 7.0.0 to 7.0.1 #19464
  • Bump actions/setup-java from 5.2.0 to 5.3.0 #19352
  • Bump actions/setup-java from 5.3.0 to 5.4.0 #19380
  • Bump actions/setup-java from 5.4.0 to 5.5.0 #19430
  • Bump actions/setup-java from 5.5.0 to 5.6.0 #19453
  • Bump actions/setup-java from 5.6.0 to 5.7.0 #19501
  • Bump antora from 3.2.0-alpha.12 to 3.2.0-rc.2 in /docs #19385
  • Bump ch.qos.logback:logback-classic from 1.5.34 to 1.5.35 #19374
  • Bump ch.qos.logback:logback-classic from 1.5.35 to 1.5.36 #19389
  • Bump ch.qos.logback:logback-classic from 1.5.36 to 1.5.37 #19396
  • Bump ch.qos.logback:logback-classic from 1.5.37 to 1.5.38 #19431
  • Bump ch.qos.logback:logback-classic from 1.5.38 to 1.6.0 #19467
  • Bump ch.qos.logback:logback-classic from 1.6.0 to 1.6.1 #19476
  • Bump ch.qos.logback:logback-classic from 1.6.1 to 1.6.2 #19556
  • Bump ch.qos.logback:logback-classic from 1.6.2 to 1.6.3 #19564
  • Bump com.fasterxml.jackson:jackson-bom from 2.22.0 to 2.22.1 #19419
  • Bump com.fasterxml.jackson:jackson-bom from 2.22.1 to 2.22.2 #19566
  • Bump com.nimbusds:oauth2-oidc-sdk from 11.37.2 to 11.38.1 #19439
  • Bump com.nimbusds:oauth2-oidc-sdk from 11.38.1 to 11.38.2 #19525
  • Bump com.unboundid:unboundid-ldapsdk from 7.0.4 to 7.0.5 #19322
  • Bump com.webauthn4j:webauthn4j-core from 0.31.6.RELEASE to 0.31.7.RELEASE #19313
  • Bump com.webauthn4j:webauthn4j-core from 0.31.7.RELEASE to 0.31.8.RELEASE #19409
  • Bump com.webauthn4j:webauthn4j-core from 0.31.8.RELEASE to 0.31.9.RELEASE #19496
  • Bump gradle-wrapper from 9.5.1 to 9.6.0 #19360
  • Bump gradle-wrapper from 9.6.0 to 9.6.1 #19393
  • Bump gradle-wrapper from 9.6.1 to 9.7.0 #19516
  • Bump io.spring.nullability:io.spring.nullability.gradle.plugin from 0.0.13 to 0.0.14 #19378
  • Bump org-bouncycastle from 1.84 to 1.85 #19437
  • Bump org-jetbrains-kotlin from 2.4.0 to 2.4.10 #19447

... (truncated)

Commits
  • a825937 Release 7.1.1
  • 74c91f8 Update to Spring Data 2026.0.1
  • b822214 Update to Spring LDAP 4.1.1
  • 39da00f Update to Micrometer 1.17.1
  • 4be80b7 Update to Reactor 2025.0.7
  • 564a677 Update to Spring Framework 7.0.9
  • 2930198 Configure Build for Commercial Repositories
  • 25f9a91 Configure with Commercial Workflows
  • bf8569f Remove OSS CI configuration
  • dcee218 Use jspecify Nullable in DPoPProofReplayValidator
  • Additional commits viewable in compare view

Updates org.springframework.boot:spring-boot-dependencies from 4.1.0 to 4.1.1

Release notes

Sourced from org.springframework.boot:spring-boot-dependencies's releases.

v4.1.1

⚠️ Attention Required

  • Spring Boot's Gradle plugin no longer automatically configures gRPC when the Protobuf plugin is applied. This behavior caused problems for those using Protobuf without gRPC. To opt in to the configuration of gRPC, configure the protobuf extension with the grpc plugin using an empty block. The Spring Boot Gradle plugin will then automatically configure the use of protoc-gen-grpc-java as before. #50822

🐞 Bug Fixes

  • Kafka consumer-specific security protocol is not taken into account #51369
  • Structured logging: a failed JSON encode corrupts the next log event written on the same thread #51156
  • Micrometer registries pin the application context #51135
  • Temporary file is not deleted when ExportedImageTar construction fails #51132
  • Metadata annotation processor ignores getter-level @NestedConfigurationProperty for records #51098
  • spring-boot-h2-console pulls servlet-api as transitive dependency #51095
  • PropertiesLauncher does not log nested archive paths #51089
  • Methods that return the result of Map#remove are not declared with a @Nullable return type #51087
  • NativeImageResourceProvider flattens Flyway migration paths in subdirectories #50964
  • Fix ordering of Kotlinx Serialization CodecCustomizer #50961
  • JarFile is not closed when finding main class from archive #50959
  • Application-managed JUL bridge handler should only be removed if installed #50950
  • CloudFoundry reactive auto-configuration should not require a WebClient.Builder bean to be defined #50944
  • Context refresh fails on reactive Cloud Foundry when using Actuator without spring-boot-health #50942
  • Resources are not cleaned up when resolving an image that is not yet present in the builder #50941
  • GraphQlWebMvcAutoConfiguration should apply customizers in order #50914
  • Auto-configured RedisMessageListenerContainer does not use virtual threads when spring.threads.virtual.enabled is true #50884
  • Context refresh fails when using Actuator on Jersey without spring-boot-health #50872
  • Context refresh fails on Cloud Foundry when using Actuator without spring-boot-health #50871
  • IllegalStateException when binding properties to a @Validated class that contains a map whose value type is a wildcard #50856
  • High number of connections due to Mongo health indicator #50852
  • Inconsistent handling of empty string values of spring.security.oauth2.resourceserver.jwt issuer-uri and jwk-set-uri #50849
  • Return type nullability of ApplicationContextAssert's getBean methods does not indicate that bean may be null #50845
  • PropertiesWebClientHttpServiceGroupConfigurer has highest precedence, preventing other configurers from being ordered ahead of it #50843
  • Exposing gRPC test server port should backoff if gRPC is not present #50825
  • JpaBaseConfiguration#entityManagerConfiguration can cause a dependency loop on beans declaring AsyncTaskExecutor #50801
  • spring.grpc.server.health.include-overall-health is not taken into account #50799
  • Setting 'server.servlet.session.cookie.partitioned' to false still emits the 'Partitioned' cookie attribute #50790
  • Managed version of Prometheus Client is not aligned with Micrometer's micrometer-registry-prometheus #50780
  • Map properties bound from empty strings fail with ConverterNotFoundException #50773
  • Protobuf Common Protos should not be a managed dependency #50772
  • An application that depends on spring-boot-security-oauth2-resource-server may fail to start with a ClassNotFoundException when Reactor is on the classpath but WebFlux is not #50764
  • W3CHeaderParser's decoding is not compliant with RFC 3986 #50650

📔 Documentation

  • Description of spring.graphql.websocket.connection-init-timeout does not render correctly in the reference guide #51348
  • spring.profiles.group should have a 'spring-profile-name' hint provider #51284
  • Remove reference to removed InfluxDB auto-configuration #51176
  • Use JacksonJsonSerde in Kafka Streams documentation #51161
  • Document alternatives to HttpMessageConverters #51129
  • Fix stale type reference for OTLP logging transport metadata #51119
  • Metadata for spring.test.mockmvc.htmlunit.url declares the wrong type #51115

... (truncated)

Commits
  • 6fdf67e Release 4.1.1
  • fde599b Upgrade to Spring Pulsar 2.0.7
  • 9daa58f Upgrade to Spring HATEOAS 3.1.2
  • 353993e Upgrade to Spring Data Bom 2026.0.1
  • 24ba596 Upgrade to Spring Session 4.1.1
  • 5cb5c29 Upgrade to Spring Security 7.1.1
  • 4adc8eb Upgrade to Spring LDAP 4.1.1
  • 4d9c19c Upgrade to Spring Kafka 4.1.1
  • f30f612 Upgrade to Spring Integration 7.1.1
  • b930283 Upgrade to Spring gRPC 1.1.1
  • Additional commits viewable in compare view

Updates org.springframework.boot:spring-boot-starter-test from 4.1.0 to 4.1.1

Release notes

Sourced from org.springframework.boot:spring-boot-starter-test's releases.

v4.1.1

⚠️ Attention Required

  • Spring Boot's Gradle plugin no longer automatically configures gRPC when the Protobuf plugin is applied. This behavior caused problems for those using Protobuf without gRPC. To opt in to the configuration of gRPC, configure the protobuf extension with the grpc plugin using an empty block. The Spring Boot Gradle plugin will then automatically configure the use of protoc-gen-grpc-java as before. #50822

🐞 Bug Fixes

  • Kafka consumer-specific security protocol is not taken into account #51369
  • Structured logging: a failed JSON encode corrupts the next log event written on the same thread #51156
  • Micrometer registries pin the application context #51135
  • Temporary file is not deleted when ExportedImageTar construction fails #51132
  • Metadata annotation processor ignores getter-level @NestedConfigurationProperty for records #51098
  • spring-boot-h2-console pulls servlet-api as transitive dependency #51095
  • PropertiesLauncher does not log nested archive paths #51089
  • Methods that return the result of Map#remove are not declared with a @Nullable return type #51087
  • NativeImageResourceProvider flattens Flyway migration paths in subdirectories #50964
  • Fix ordering of Kotlinx Serialization CodecCustomizer #50961
  • JarFile is not closed when finding main class from archive #50959
  • Application-managed JUL bridge handler should only be removed if installed #50950
  • CloudFoundry reactive auto-configuration should not require a WebClient.Builder bean to be defined #50944
  • Context refresh fails on reactive Cloud Foundry when using Actuator without spring-boot-health #50942
  • Resources are not cleaned up when resolving an image that is not yet present in the builder #50941
  • GraphQlWebMvcAutoConfiguration should apply customizers in order #50914
  • Auto-configured RedisMessageListenerContainer does not use virtual threads when spring.threads.virtual.enabled is true #50884
  • Context refresh fails when using Actuator on Jersey without spring-boot-health #50872
  • Context refresh fails on Cloud Foundry when using Actuator without spring-boot-health #50871
  • IllegalStateException when binding properties to a @Validated class that contains a map whose value type is a wildcard #50856
  • High number of connections due to Mongo health indicator #50852
  • Inconsistent handling of empty string values of spring.security.oauth2.resourceserver.jwt issuer-uri and jwk-set-uri #50849
  • Return type nullability of ApplicationContextAssert's getBean methods does not indicate that bean may be null #50845
  • PropertiesWebClientHttpServiceGroupConfigurer has highest precedence, preventing other configurers from being ordered ahead of it #50843
  • Exposing gRPC test server port should backoff if gRPC is not present #50825
  • JpaBaseConfiguration#entityManagerConfiguration can cause a dependency loop on beans declaring AsyncTaskExecutor #50801
  • spring.grpc.server.health.include-overall-health is not taken into account #50799
  • Setting 'server.servlet.session.cookie.partitioned' to false still emits the 'Partitioned' cookie attribute #50790
  • Managed version of Prometheus Client is not aligned with Micrometer's micrometer-registry-prometheus #50780
  • Map properties bound from empty strings fail with ConverterNotFoundException #50773
  • Protobuf Common Protos should not be a managed dependency #50772
  • An application that depends on spring-boot-security-oauth2-resource-server may fail to start with a ClassNotFoundException when Reactor is on the classpath but WebFlux is not #50764
  • W3CHeaderParser's decoding is not compliant with RFC 3986 #50650

📔 Documentation

  • Description of spring.graphql.websocket.connection-init-timeout does not render correctly in the reference guide #51348
  • spring.profiles.group should have a 'spring-profile-name' hint provider #51284
  • Remove reference to removed InfluxDB auto-configuration #51176
  • Use JacksonJsonSerde in Kafka Streams documentation #51161
  • Document alternatives to HttpMessageConverters #51129
  • Fix stale type reference for OTLP logging transport metadata #51119
  • Metadata for spring.test.mockmvc.htmlunit.url declares the wrong type #51115

... (truncated)

Commits
  • 6fdf67e Release 4.1.1
  • fde599b Upgrade to Spring Pulsar 2.0.7
  • 9daa58f Upgrade to Spring HATEOAS 3.1.2
  • 353993e Upgrade to Spring Data Bom 2026.0.1
  • 24ba596 Upgrade to Spring Session 4.1.1
  • 5cb5c29 Upgrade to Spring Security 7.1.1
  • 4adc8eb Upgrade to Spring LDAP 4.1.1
  • 4d9c19c Upgrade to Spring Kafka 4.1.1
  • f30f612 Upgrade to Spring Integration 7.1.1
  • b930283 Upgrade to Spring gRPC 1.1.1
  • Additional commits viewable in compare view

Updates org.springframework.boot:spring-boot-autoconfigure from 4.1.0 to 4.1.1

Release notes

Sourced from org.springframework.boot:spring-boot-autoconfigure's releases.

v4.1.1

⚠️ Attention Required

  • Spring Boot's Gradle plugin no longer automatically configures gRPC when the Protobuf plugin is applied. This behavior caused problems for those using Protobuf without gRPC. To opt in to the configuration of gRPC, configure the protobuf extension with the grpc plugin using an empty block. The Spring Boot Gradle plugin will then automatically configure the use of protoc-gen-grpc-java as before. #50822

🐞 Bug Fixes

  • Kafka consumer-specific security protocol is not taken into account #51369
  • Structured logging: a failed JSON encode corrupts the next log event written on the same thread #51156
  • Micrometer registries pin the application context #51135
  • Temporary file is not deleted when ExportedImageTar construction fails #51132
  • Metadata annotation processor ignores getter-level @NestedConfigurationProperty for records #51098
  • spring-boot-h2-console pulls servlet-api as transitive dependency #51095
  • PropertiesLauncher does not log nested archive paths #51089
  • Methods that return the result of Map#remove are not declared with a @Nullable return type #51087
  • NativeImageResourceProvider flattens Flyway migration paths in subdirectories #50964
  • Fix ordering of Kotlinx Serialization CodecCustomizer #50961
  • JarFile is not closed when finding main class from archive #50959
  • Application-managed JUL bridge handler should only be removed if installed #50950
  • CloudFoundry reactive auto-configuration should not require a WebClient.Builder bean to be defined #50944
  • Context refresh fails on reactive Cloud Foundry when using Actuator without spring-boot-health #50942
  • Resources are not cleaned up when resolving an image that is not yet present in the builder #50941
  • GraphQlWebMvcAutoConfiguration should apply customizers in order #50914
  • Auto-configured RedisMessageListenerContainer does not use virtual threads when spring.threads.virtual.enabled is true #50884
  • Context refresh fails when using Actuator on Jersey without spring-boot-health #50872
  • Context refresh fails on Cloud Foundry when using Actuator without spring-boot-health #50871
  • IllegalStateException when binding properties to a @Validated class that contains a map whose value type is a wildcard #50856
  • High number of connections due to Mongo health indicator #50852
  • Inconsistent handling of empty string values of spring.security.oauth2.resourceserver.jwt issuer-uri and jwk-set-uri #50849
  • Return type nullability of ApplicationContextAssert's getBean methods does not indicate that bean may be null #50845
  • PropertiesWebClientHttpServiceGroupConfigurer has highest precedence, preventing other configurers from being ordered ahead of it #50843
  • Exposing gRPC test server port should backoff if gRPC is not present #50825
  • JpaBaseConfiguration#entityManagerConfiguration can cause a dependency loop on beans declaring AsyncTaskExecutor #50801
  • spring.grpc.server.health.include-overall-health is not taken into account #50799
  • Setting 'server.servlet.session.cookie.partitioned' to false still emits the 'Partitioned' cookie attribute #50790
  • Managed version of Prometheus Client is not aligned with Micrometer's micrometer-registry-prometheus #50780
  • Map properties bound from empty strings fail with ConverterNotFoundException #50773
  • Protobuf Common Protos should not be a managed dependency #50772
  • An application that depends on spring-boot-security-oauth2-resource-server may fail to start with a ClassNotFoundException when Reactor is on the classpath but WebFlux is not #50764
  • W3CHeaderParser's decoding is not compliant with RFC 3986 #50650

📔 Documentation

  • Description of spring.graphql.websocket.connection-init-timeout does not render correctly in the reference guide #51348
  • spring.profiles.group should have a 'spring-profile-name' hint provider #51284
  • Remove reference to removed InfluxDB auto-configuration #51176
  • Use JacksonJsonSerde in Kafka Streams documentation #51161
  • Document alternatives to HttpMessageConverters #51129
  • Fix stale type reference for OTLP logging transport metadata #51119
  • Metadata for spring.test.mockmvc.htmlunit.url declares the wrong type Description has been truncated

@dependabot dependabot Bot added dependencies Pull requests that update a dependency file java Pull requests that update Java code labels Aug 24, 2026
…updates

Bumps the prod-deps-ver group with 22 updates in the / directory:

| Package | From | To |
| --- | --- | --- |
| [org.junit:junit-bom](https://github.com/junit-team/junit-framework) | `6.1.2` | `6.1.3` |
| [org.junit.jupiter:junit-jupiter-engine](https://github.com/junit-team/junit-framework) | `6.1.2` | `6.1.3` |
| [org.junit.jupiter:junit-jupiter-params](https://github.com/junit-team/junit-framework) | `6.1.2` | `6.1.3` |
| [org.junit.jupiter:junit-jupiter-api](https://github.com/junit-team/junit-framework) | `6.1.2` | `6.1.3` |
| [org.eclipse.jetty:jetty-bom](https://github.com/jetty/jetty.project) | `12.1.11` | `12.1.12` |
| org.eclipse.jetty.ee10:jetty-ee10-servlet | `12.1.11` | `12.1.12` |
| org.eclipse.jetty.ee10:jetty-ee10-webapp | `12.1.11` | `12.1.12` |
| [org.springframework.security:spring-security-bom](https://github.com/spring-projects/spring-security) | `7.1.0` | `7.1.1` |
| [org.springframework.security:spring-security-core](https://github.com/spring-projects/spring-security) | `7.1.0` | `7.1.1` |
| [org.springframework.boot:spring-boot-dependencies](https://github.com/spring-projects/spring-boot) | `4.1.0` | `4.1.1` |
| [org.springframework.boot:spring-boot-starter-test](https://github.com/spring-projects/spring-boot) | `4.1.0` | `4.1.1` |
| [org.springframework.boot:spring-boot-autoconfigure](https://github.com/spring-projects/spring-boot) | `4.1.0` | `4.1.1` |
| [org.springframework.boot:spring-boot-starter-tomcat](https://github.com/spring-projects/spring-boot) | `4.1.0` | `4.1.1` |
| [org.springframework:spring-core](https://github.com/spring-projects/spring-framework) | `7.0.8` | `7.0.9` |
| [org.springframework:spring-web](https://github.com/spring-projects/spring-framework) | `7.0.8` | `7.0.9` |
| [org.springframework:spring-aop](https://github.com/spring-projects/spring-framework) | `7.0.8` | `7.0.9` |
| [org.springframework:spring-beans](https://github.com/spring-projects/spring-framework) | `7.0.8` | `7.0.9` |
| [org.springframework.security:spring-security-oauth2-client](https://github.com/spring-projects/spring-security) | `7.1.0` | `7.1.1` |
| [com.github.spotbugs:spotbugs-annotations](https://github.com/spotbugs/spotbugs) | `4.10.3` | `4.10.4` |
| [io.projectreactor:reactor-core](https://github.com/reactor/reactor-core) | `3.8.2` | `3.8.7` |
| [io.projectreactor:reactor-test](https://github.com/reactor/reactor-core) | `3.8.2` | `3.8.7` |
| [com.github.spotbugs:spotbugs-maven-plugin](https://github.com/spotbugs/spotbugs-maven-plugin) | `4.10.3.0` | `4.10.4.0` |



Updates `org.junit:junit-bom` from 6.1.2 to 6.1.3
- [Release notes](https://github.com/junit-team/junit-framework/releases)
- [Commits](junit-team/junit-framework@r6.1.2...r6.1.3)

Updates `org.junit.jupiter:junit-jupiter-engine` from 6.1.2 to 6.1.3
- [Release notes](https://github.com/junit-team/junit-framework/releases)
- [Commits](junit-team/junit-framework@r6.1.2...r6.1.3)

Updates `org.junit.jupiter:junit-jupiter-params` from 6.1.2 to 6.1.3
- [Release notes](https://github.com/junit-team/junit-framework/releases)
- [Commits](junit-team/junit-framework@r6.1.2...r6.1.3)

Updates `org.junit.jupiter:junit-jupiter-api` from 6.1.2 to 6.1.3
- [Release notes](https://github.com/junit-team/junit-framework/releases)
- [Commits](junit-team/junit-framework@r6.1.2...r6.1.3)

Updates `org.eclipse.jetty:jetty-bom` from 12.1.11 to 12.1.12
- [Release notes](https://github.com/jetty/jetty.project/releases)
- [Commits](jetty/jetty.project@jetty-12.1.11...jetty-12.1.12)

Updates `org.eclipse.jetty.ee10:jetty-ee10-servlet` from 12.1.11 to 12.1.12

Updates `org.eclipse.jetty.ee10:jetty-ee10-webapp` from 12.1.11 to 12.1.12

Updates `org.springframework.security:spring-security-bom` from 7.1.0 to 7.1.1
- [Release notes](https://github.com/spring-projects/spring-security/releases)
- [Changelog](https://github.com/spring-projects/spring-security/blob/main/RELEASE.adoc)
- [Commits](spring-projects/spring-security@7.1.0...7.1.1)

Updates `org.springframework.security:spring-security-core` from 7.1.0 to 7.1.1
- [Release notes](https://github.com/spring-projects/spring-security/releases)
- [Changelog](https://github.com/spring-projects/spring-security/blob/main/RELEASE.adoc)
- [Commits](spring-projects/spring-security@7.1.0...7.1.1)

Updates `org.springframework.boot:spring-boot-dependencies` from 4.1.0 to 4.1.1
- [Release notes](https://github.com/spring-projects/spring-boot/releases)
- [Commits](spring-projects/spring-boot@v4.1.0...v4.1.1)

Updates `org.springframework.boot:spring-boot-starter-test` from 4.1.0 to 4.1.1
- [Release notes](https://github.com/spring-projects/spring-boot/releases)
- [Commits](spring-projects/spring-boot@v4.1.0...v4.1.1)

Updates `org.springframework.boot:spring-boot-autoconfigure` from 4.1.0 to 4.1.1
- [Release notes](https://github.com/spring-projects/spring-boot/releases)
- [Commits](spring-projects/spring-boot@v4.1.0...v4.1.1)

Updates `org.springframework.boot:spring-boot-starter-tomcat` from 4.1.0 to 4.1.1
- [Release notes](https://github.com/spring-projects/spring-boot/releases)
- [Commits](spring-projects/spring-boot@v4.1.0...v4.1.1)

Updates `org.springframework:spring-core` from 7.0.8 to 7.0.9
- [Release notes](https://github.com/spring-projects/spring-framework/releases)
- [Commits](spring-projects/spring-framework@v7.0.8...v7.0.9)

Updates `org.springframework:spring-web` from 7.0.8 to 7.0.9
- [Release notes](https://github.com/spring-projects/spring-framework/releases)
- [Commits](spring-projects/spring-framework@v7.0.8...v7.0.9)

Updates `org.springframework:spring-aop` from 7.0.8 to 7.0.9
- [Release notes](https://github.com/spring-projects/spring-framework/releases)
- [Commits](spring-projects/spring-framework@v7.0.8...v7.0.9)

Updates `org.springframework:spring-beans` from 7.0.8 to 7.0.9
- [Release notes](https://github.com/spring-projects/spring-framework/releases)
- [Commits](spring-projects/spring-framework@v7.0.8...v7.0.9)

Updates `org.springframework:spring-web` from 6.2.18 to 7.0.9
- [Release notes](https://github.com/spring-projects/spring-framework/releases)
- [Commits](spring-projects/spring-framework@v7.0.8...v7.0.9)

Updates `org.springframework:spring-aop` from 7.0.8 to 7.0.9
- [Release notes](https://github.com/spring-projects/spring-framework/releases)
- [Commits](spring-projects/spring-framework@v7.0.8...v7.0.9)

Updates `org.springframework:spring-beans` from 7.0.8 to 7.0.9
- [Release notes](https://github.com/spring-projects/spring-framework/releases)
- [Commits](spring-projects/spring-framework@v7.0.8...v7.0.9)

Updates `org.springframework.security:spring-security-oauth2-client` from 7.1.0 to 7.1.1
- [Release notes](https://github.com/spring-projects/spring-security/releases)
- [Changelog](https://github.com/spring-projects/spring-security/blob/main/RELEASE.adoc)
- [Commits](spring-projects/spring-security@7.1.0...7.1.1)

Updates `com.github.spotbugs:spotbugs-annotations` from 4.10.3 to 4.10.4
- [Release notes](https://github.com/spotbugs/spotbugs/releases)
- [Changelog](https://github.com/spotbugs/spotbugs/blob/master/CHANGELOG.md)
- [Commits](spotbugs/spotbugs@4.10.3...4.10.4)

Updates `io.projectreactor:reactor-core` from 3.8.2 to 3.8.7
- [Release notes](https://github.com/reactor/reactor-core/releases)
- [Commits](reactor/reactor-core@v3.8.2...v3.8.7)

Updates `io.projectreactor:reactor-test` from 3.8.2 to 3.8.7
- [Release notes](https://github.com/reactor/reactor-core/releases)
- [Commits](reactor/reactor-core@v3.8.2...v3.8.7)

Updates `org.springframework.boot:spring-boot-starter-test` from 3.5.14 to 4.1.1
- [Release notes](https://github.com/spring-projects/spring-boot/releases)
- [Commits](spring-projects/spring-boot@v4.1.0...v4.1.1)

Updates `com.github.spotbugs:spotbugs-maven-plugin` from 4.10.3.0 to 4.10.4.0
- [Release notes](https://github.com/spotbugs/spotbugs-maven-plugin/releases)
- [Commits](spotbugs/spotbugs-maven-plugin@spotbugs-maven-plugin-4.10.3.0...spotbugs-maven-plugin-4.10.4.0)

Updates `org.junit.jupiter:junit-jupiter-engine` from 6.1.2 to 6.1.3
- [Release notes](https://github.com/junit-team/junit-framework/releases)
- [Commits](junit-team/junit-framework@r6.1.2...r6.1.3)

Updates `org.junit.jupiter:junit-jupiter-params` from 6.1.2 to 6.1.3
- [Release notes](https://github.com/junit-team/junit-framework/releases)
- [Commits](junit-team/junit-framework@r6.1.2...r6.1.3)

Updates `org.springframework.security:spring-security-core` from 7.1.0 to 7.1.1
- [Release notes](https://github.com/spring-projects/spring-security/releases)
- [Changelog](https://github.com/spring-projects/spring-security/blob/main/RELEASE.adoc)
- [Commits](spring-projects/spring-security@7.1.0...7.1.1)

Updates `org.springframework.boot:spring-boot-autoconfigure` from 3.5.14 to 4.1.1
- [Release notes](https://github.com/spring-projects/spring-boot/releases)
- [Commits](spring-projects/spring-boot@v4.1.0...v4.1.1)

Updates `org.springframework.boot:spring-boot-starter-tomcat` from 3.5.14 to 4.1.1
- [Release notes](https://github.com/spring-projects/spring-boot/releases)
- [Commits](spring-projects/spring-boot@v4.1.0...v4.1.1)

Updates `org.junit.jupiter:junit-jupiter-api` from 6.1.2 to 6.1.3
- [Release notes](https://github.com/junit-team/junit-framework/releases)
- [Commits](junit-team/junit-framework@r6.1.2...r6.1.3)

Updates `org.eclipse.jetty.ee10:jetty-ee10-servlet` from 12.1.11 to 12.1.12

Updates `org.eclipse.jetty.ee10:jetty-ee10-webapp` from 12.1.11 to 12.1.12

---
updated-dependencies:
- dependency-name: com.github.spotbugs:spotbugs-annotations
  dependency-version: 4.10.4
  dependency-type: direct:production
  update-type: version-update:semver-patch
  dependency-group: prod-deps-ver
- dependency-name: com.github.spotbugs:spotbugs-maven-plugin
  dependency-version: 4.10.4.0
  dependency-type: direct:production
  update-type: version-update:semver-patch
  dependency-group: prod-deps-ver
- dependency-name: io.projectreactor:reactor-core
  dependency-version: 3.8.7
  dependency-type: direct:production
  update-type: version-update:semver-patch
  dependency-group: prod-deps-ver
- dependency-name: io.projectreactor:reactor-test
  dependency-version: 3.8.7
  dependency-type: direct:production
  update-type: version-update:semver-patch
  dependency-group: prod-deps-ver
- dependency-name: org.eclipse.jetty.ee10:jetty-ee10-servlet
  dependency-version: 12.1.12
  dependency-type: direct:production
  update-type: version-update:semver-patch
  dependency-group: prod-deps-ver
- dependency-name: org.eclipse.jetty.ee10:jetty-ee10-servlet
  dependency-version: 12.1.12
  dependency-type: direct:production
  update-type: version-update:semver-patch
  dependency-group: prod-deps-ver
- dependency-name: org.eclipse.jetty.ee10:jetty-ee10-webapp
  dependency-version: 12.1.12
  dependency-type: direct:production
  update-type: version-update:semver-patch
  dependency-group: prod-deps-ver
- dependency-name: org.eclipse.jetty.ee10:jetty-ee10-webapp
  dependency-version: 12.1.12
  dependency-type: direct:production
  update-type: version-update:semver-patch
  dependency-group: prod-deps-ver
- dependency-name: org.eclipse.jetty:jetty-bom
  dependency-version: 12.1.12
  dependency-type: direct:production
  update-type: version-update:semver-patch
  dependency-group: prod-deps-ver
- dependency-name: org.junit.jupiter:junit-jupiter-api
  dependency-version: 6.1.3
  dependency-type: direct:production
  update-type: version-update:semver-patch
  dependency-group: prod-deps-ver
- dependency-name: org.junit.jupiter:junit-jupiter-api
  dependency-version: 6.1.3
  dependency-type: direct:production
  update-type: version-update:semver-patch
  dependency-group: prod-deps-ver
- dependency-name: org.junit.jupiter:junit-jupiter-engine
  dependency-version: 6.1.3
  dependency-type: direct:production
  update-type: version-update:semver-patch
  dependency-group: prod-deps-ver
- dependency-name: org.junit.jupiter:junit-jupiter-engine
  dependency-version: 6.1.3
  dependency-type: direct:production
  update-type: version-update:semver-patch
  dependency-group: prod-deps-ver
- dependency-name: org.junit.jupiter:junit-jupiter-params
  dependency-version: 6.1.3
  dependency-type: direct:production
  update-type: version-update:semver-patch
  dependency-group: prod-deps-ver
- dependency-name: org.junit.jupiter:junit-jupiter-params
  dependency-version: 6.1.3
  dependency-type: direct:production
  update-type: version-update:semver-patch
  dependency-group: prod-deps-ver
- dependency-name: org.junit:junit-bom
  dependency-version: 6.1.3
  dependency-type: direct:production
  update-type: version-update:semver-patch
  dependency-group: prod-deps-ver
- dependency-name: org.springframework.boot:spring-boot-autoconfigure
  dependency-version: 4.1.1
  dependency-type: direct:production
  update-type: version-update:semver-major
  dependency-group: prod-deps-ver
- dependency-name: org.springframework.boot:spring-boot-autoconfigure
  dependency-version: 4.1.1
  dependency-type: direct:production
  update-type: version-update:semver-patch
  dependency-group: prod-deps-ver
- dependency-name: org.springframework.boot:spring-boot-dependencies
  dependency-version: 4.1.1
  dependency-type: direct:production
  update-type: version-update:semver-patch
  dependency-group: prod-deps-ver
- dependency-name: org.springframework.boot:spring-boot-starter-test
  dependency-version: 4.1.1
  dependency-type: direct:production
  update-type: version-update:semver-major
  dependency-group: prod-deps-ver
- dependency-name: org.springframework.boot:spring-boot-starter-test
  dependency-version: 4.1.1
  dependency-type: direct:production
  update-type: version-update:semver-patch
  dependency-group: prod-deps-ver
- dependency-name: org.springframework.boot:spring-boot-starter-tomcat
  dependency-version: 4.1.1
  dependency-type: direct:production
  update-type: version-update:semver-major
  dependency-group: prod-deps-ver
- dependency-name: org.springframework.boot:spring-boot-starter-tomcat
  dependency-version: 4.1.1
  dependency-type: direct:production
  update-type: version-update:semver-patch
  dependency-group: prod-deps-ver
- dependency-name: org.springframework.security:spring-security-bom
  dependency-version: 7.1.1
  dependency-type: direct:production
  update-type: version-update:semver-patch
  dependency-group: prod-deps-ver
- dependency-name: org.springframework.security:spring-security-core
  dependency-version: 7.1.1
  dependency-type: direct:production
  update-type: version-update:semver-patch
  dependency-group: prod-deps-ver
- dependency-name: org.springframework.security:spring-security-core
  dependency-version: 7.1.1
  dependency-type: direct:production
  update-type: version-update:semver-patch
  dependency-group: prod-deps-ver
- dependency-name: org.springframework.security:spring-security-oauth2-client
  dependency-version: 7.1.1
  dependency-type: direct:production
  update-type: version-update:semver-patch
  dependency-group: prod-deps-ver
- dependency-name: org.springframework:spring-aop
  dependency-version: 7.0.9
  dependency-type: direct:production
  update-type: version-update:semver-patch
  dependency-group: prod-deps-ver
- dependency-name: org.springframework:spring-aop
  dependency-version: 7.0.9
  dependency-type: direct:production
  update-type: version-update:semver-patch
  dependency-group: prod-deps-ver
- dependency-name: org.springframework:spring-beans
  dependency-version: 7.0.9
  dependency-type: direct:production
  update-type: version-update:semver-patch
  dependency-group: prod-deps-ver
- dependency-name: org.springframework:spring-beans
  dependency-version: 7.0.9
  dependency-type: direct:production
  update-type: version-update:semver-patch
  dependency-group: prod-deps-ver
- dependency-name: org.springframework:spring-core
  dependency-version: 7.0.9
  dependency-type: direct:production
  update-type: version-update:semver-patch
  dependency-group: prod-deps-ver
- dependency-name: org.springframework:spring-web
  dependency-version: 7.0.9
  dependency-type: direct:production
  update-type: version-update:semver-major
  dependency-group: prod-deps-ver
- dependency-name: org.springframework:spring-web
  dependency-version: 7.0.9
  dependency-type: direct:production
  update-type: version-update:semver-patch
  dependency-group: prod-deps-ver
...

Signed-off-by: dependabot[bot] <support@github.com>
@dependabot
dependabot Bot force-pushed the dependabot/maven/prod-deps-ver-6fecf740a5 branch from e44d9e4 to 702b317 Compare August 26, 2026 07:02
NiklasHerrmann21 added a commit that referenced this pull request Aug 31, 2026
Pulls the pending Dependabot dependency bumps into this branch and also
raises the legacy Spring Boot 3.x / Framework 6.x versions used by the
spring-security-3 module to the same latest minor/patch releases already
applied on the main-3.x line.

4.x line:
- Spring Boot 4.1.0 → 4.1.1, Spring Framework 7.0.8 → 7.0.9,
  Spring Security 7.1.0 → 7.1.1
- Jetty 12.1.11 → 12.1.12, Reactor (core & test) 3.8.6 → 3.8.7
- JUnit Jupiter 6.1.2 → 6.1.3
- SpotBugs annotations 4.10.3 → 4.10.4, plugin 4.10.3.0 → 4.10.4.0
- logcaptor (test) 2.12.6 → 2.12.7

legacy3 (spring-security-3):
- Spring Boot 3.5.14 → 3.5.16, Spring Framework 6.2.18 → 6.2.19,
  Spring Security 6.5.10 → 6.5.11, Reactor 3.8.2 → 3.8.7

Full reactor build (mvn clean install) green across all 13 modules.
NiklasHerrmann21 added a commit that referenced this pull request Aug 31, 2026
* fix: ensure HybridTokenAuthenticator honours explicit service configurations for token validation

The IAS and XSUAA delegate authenticators were constructed without their
configurations, causing them to fall back to Environments.getCurrent() at
request time instead of using the configurations explicitly passed to
HybridTokenAuthenticator. The supplied HTTP client was similarly ignored
by the delegates.

The constructor now forwards all three inputs (iasConfig, xsuaaConfig,
httpClient) to both delegates via the existing withServiceConfiguration /
withHttpClient fluent API. Callers that follow the documented pattern of
loading configurations from Environments.getCurrent() are unaffected —
the delegates resolve to the same values they would have before.

Adds HybridTokenAuthenticatorConfigurationTest with real delegates (no
reflection-based mock replacement) to cover:
- IAS token for an ambient binding is rejected when a different config is supplied
- XSUAA token for an ambient binding is rejected when a different config is supplied
- Explicitly supplied config is used even when no ambient config exists

* docs: add 4.1.2 CHANGELOG entry and replace fixed version refs in README with 4.x

README What's New section and related version callouts updated from
hardcoded patch versions (4.0.1, 4.0.3, 7.0.5, 7.0.3) to version-agnostic
4.x / 7.x wording so the section stays accurate without per-release edits.

* removed readme change from CHANGELOG.md

* chore: Bump project version 4.1.1 → 4.1.2 across all modules, READMEs and samples

* chore: update dependencies (Dependabot PRs #2020/#2021/#2025 + legacy3)

Pulls the pending Dependabot dependency bumps into this branch and also
raises the legacy Spring Boot 3.x / Framework 6.x versions used by the
spring-security-3 module to the same latest minor/patch releases already
applied on the main-3.x line.

4.x line:
- Spring Boot 4.1.0 → 4.1.1, Spring Framework 7.0.8 → 7.0.9,
  Spring Security 7.1.0 → 7.1.1
- Jetty 12.1.11 → 12.1.12, Reactor (core & test) 3.8.6 → 3.8.7
- JUnit Jupiter 6.1.2 → 6.1.3
- SpotBugs annotations 4.10.3 → 4.10.4, plugin 4.10.3.0 → 4.10.4.0
- logcaptor (test) 2.12.6 → 2.12.7

legacy3 (spring-security-3):
- Spring Boot 3.5.14 → 3.5.16, Spring Framework 6.2.18 → 6.2.19,
  Spring Security 6.5.10 → 6.5.11, Reactor 3.8.2 → 3.8.7

Full reactor build (mvn clean install) green across all 13 modules.
@dependabot @github

dependabot Bot commented on behalf of github Aug 31, 2026

Copy link
Copy Markdown
Contributor Author

Looks like these dependencies are no longer updatable, so this is no longer needed.

@dependabot dependabot Bot closed this Aug 31, 2026
@dependabot
dependabot Bot deleted the dependabot/maven/prod-deps-ver-6fecf740a5 branch August 31, 2026 12:05
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

dependencies Pull requests that update a dependency file java Pull requests that update Java code

Projects

None yet

Development

Successfully merging this pull request may close these issues.

0 participants