Update dependency org.springframework.security:spring-security-crypto to v6.4.0 #26

Merged
Renovate Bot (Automatisiert) merged 1 commits from renovate/version.springsec into main 2024-11-19 01:05:42 +01:00

This PR contains the following updates:

Package Type Update Change
org.springframework.security:spring-security-crypto (source) compile minor 6.3.4 -> 6.4.0

Release Notes

spring-projects/spring-security (org.springframework.security:spring-security-crypto)

v6.4.0

Compare Source

New Features

  • Add @FunctionalInterface to AuthorizationEventPublisher #​15934
  • Add DefaultResourcesFilter.webauthn() #​15970
  • Add deprecation notice for missing leading slashes #​16020
  • Code Cleanup #​15996
  • Document passkeys dependencies #​16107
  • Factor out some common object mocking in tests #​15396
  • Fix saml2 authentication guide docs #​16017
  • Improve documentation about CredentialsContainer #​15554
  • Improve Documentation on Adding a Custom Security Filter #​15893
  • Improve Error Message for Conflicting Filter Chains #​15992
  • Make it easier to determine where a filter chain has been defined #​15874
  • OIDC logout not working for JPA/JDBC OAuth2AuthorizationService because DefaultSaml2AuthenticatedPrincipal does not implement equality #​15346
  • Polish JdbcOneTimeTokenService #​15997
  • relying-party-registration doesn't allow placeholders in xml #​14645
  • Remove unnecessary parentheses and add static final field MockPortResolver#getServerPort #​15875
  • Support ServerExchangeRejectedHandler @Bean #​16063

🪲 Bug Fixes

  • An empty-string bearer token should result in an appropriate HTTP status code #​16037
  • AuthorizeReturnObject AOT support should register proxied class as well #​16106
  • Correct class name reference in WebFilterChainProxy JavaDoc #​16004
  • Fix typo javadoc some classes #​16022
  • Initialize OpenSAML in OpenSamlAssertingPartyMetadataRepository #​16055
  • IpAddressMatcher null pointer exception #​16104
  • OpenSamlAssertingPartyMetadataRepository should initialize OpenSAML #​16042
  • Support ServerWebExchangeFirewall @Bean #​15999
  • UniqueSecurityAnnotationScanner throws ConcurrentModificationException #​15906

🔨 Dependency Upgrades

  • Bump ch.qos.logback:logback-classic from 1.5.11 to 1.5.12 #​16005
  • Bump com.fasterxml.jackson:jackson-bom from 2.18.0 to 2.18.1 #​16007
  • Bump com.webauthn4j:webauthn4j-core from 0.28.1.RELEASE to 0.28.2.RELEASE #​16122
  • Bump io.freefair.gradle:aspectj-plugin from 8.10.2 to 8.11 #​16123
  • Bump io.micrometer:micrometer-observation from 1.14.0 to 1.14.1 #​16121
  • Bump io.projectreactor:reactor-bom from 2023.0.11 to 2023.0.12 #​16079
  • Bump org-bouncycastle from 1.78.1 to 1.79 #​16010
  • Bump org.hibernate.orm:hibernate-core from 6.6.1.Final to 6.6.2.Final #​16048
  • Bump org.hsqldb:hsqldb from 2.7.3 to 2.7.4 #​16028
  • Bump org.htmlunit:htmlunit from 4.5.0 to 4.6.0 #​16044
  • Bump org.junit:junit-bom from 5.11.2 to 5.11.3 #​15968
  • Bump org.seleniumhq.selenium:htmlunit3-driver from 4.25.0 to 4.26.0 #​16043
  • Bump org.seleniumhq.selenium:selenium-java from 4.25.0 to 4.26.0 #​16018
  • Bump org.springframework.data:spring-data-bom from 2024.0.5 to 2024.1.0 #​16124
  • Bump org.springframework.ldap:spring-ldap-core from 3.2.7 to 3.2.8 #​16097
  • Bump org.springframework:spring-framework-bom from 6.2.0-RC3 to 6.2.0 #​16096

🔩 Build Updates

  • Bump @antora/collector-extension from 1.0.0-beta.4 to 1.0.0-beta.5 in /docs #​16115
  • Update Antora UI Spring to v0.4.17 #​15929

❤️ Contributors

Thank you to all the contributors who worked on this release:

@​Chu3laMan, @​Kehrlann, @​Limm-jk, @​dcolazin, @​dependabot[bot], @​franticticktick, @​github-actions[bot], @​gzhao9, @​ig-jinwoo, @​jzheaux, @​kse-music, @​ngocnhan-tran1996, and @​nomoreFt

v6.3.5

Compare Source

New Features

  • Support ServerExchangeRejectedHandler @Bean #​16062
  • Supporting logout+jwt for back-channel logout with spring-webflux #​15702

🪲 Bug Fixes

  • Align DelegatingAuthenticationConverter Constructors #​15949
  • An empty-string bearer token should result in an appropriate HTTP status code #​16036
  • IpAddressMatcher null pointer exception #​15527
  • RequestMatcherDelegatingAuthorizationManager should be post-processable #​15981
  • Support ServerWebExchangeFirewall @Bean #​15991
  • Unhandled exception in CookieRequestCache results in 500 Internal Server Error #​15986
  • Update logout.adoc: Fix Customizing Logout Success Example #​15956

🔨 Dependency Upgrades

  • Bump ch.qos.logback:logback-classic from 1.5.11 to 1.5.12 #​16006
  • Bump com.fasterxml.jackson:jackson-bom from 2.17.2 to 2.17.3 #​16032
  • Bump io.micrometer:micrometer-observation from 1.12.12 to 1.12.13 #​16126
  • Bump io.projectreactor:reactor-bom from 2023.0.11 to 2023.0.12 #​16082
  • Bump org.hsqldb:hsqldb from 2.7.3 to 2.7.4 #​16033
  • Bump org.springframework.data:spring-data-bom from 2024.0.5 to 2024.0.6 #​16125
  • Bump org.springframework.ldap:spring-ldap-core from 3.2.7 to 3.2.8 #​16102
  • Bump org.springframework:spring-framework-bom from 6.1.14 to 6.1.15 #​16101

🔩 Build Updates

  • Bump @antora/collector-extension from 1.0.0-beta.4 to 1.0.0-beta.5 in /docs #​16117
  • Update Antora UI Spring to v0.4.17 #​15930

❤️ Contributors

Thank you to all the contributors who worked on this release:

@​asimuleo, @​dependabot[bot], @​github-actions[bot], and @​kse-music


Configuration

📅 Schedule: Branch creation - At any time (no schedule defined), Automerge - At any time (no schedule defined).

🚦 Automerge: Enabled.

Rebasing: Whenever PR becomes conflicted, or you tick the rebase/retry checkbox.

🔕 Ignore: Close this PR and you won't be reminded about this update again.


  • If you want to rebase/retry this PR, check this box

This PR has been generated by Renovate Bot.

This PR contains the following updates: | Package | Type | Update | Change | |---|---|---|---| | [org.springframework.security:spring-security-crypto](https://spring.io/projects/spring-security) ([source](https://github.com/spring-projects/spring-security)) | compile | minor | `6.3.4` -> `6.4.0` | --- ### Release Notes <details> <summary>spring-projects/spring-security (org.springframework.security:spring-security-crypto)</summary> ### [`v6.4.0`](https://github.com/spring-projects/spring-security/releases/tag/6.4.0) [Compare Source](https://github.com/spring-projects/spring-security/compare/6.3.5...6.4.0) #### :star: New Features - Add `@FunctionalInterface` to AuthorizationEventPublisher [#&#8203;15934](https://github.com/spring-projects/spring-security/pull/15934) - Add DefaultResourcesFilter.webauthn() [#&#8203;15970](https://github.com/spring-projects/spring-security/pull/15970) - Add deprecation notice for missing leading slashes [#&#8203;16020](https://github.com/spring-projects/spring-security/issues/16020) - Code Cleanup [#&#8203;15996](https://github.com/spring-projects/spring-security/pull/15996) - Document passkeys dependencies [#&#8203;16107](https://github.com/spring-projects/spring-security/issues/16107) - Factor out some common object mocking in tests [#&#8203;15396](https://github.com/spring-projects/spring-security/pull/15396) - Fix saml2 authentication guide docs [#&#8203;16017](https://github.com/spring-projects/spring-security/pull/16017) - Improve documentation about CredentialsContainer [#&#8203;15554](https://github.com/spring-projects/spring-security/pull/15554) - Improve Documentation on Adding a Custom Security Filter [#&#8203;15893](https://github.com/spring-projects/spring-security/issues/15893) - Improve Error Message for Conflicting Filter Chains [#&#8203;15992](https://github.com/spring-projects/spring-security/pull/15992) - Make it easier to determine where a filter chain has been defined [#&#8203;15874](https://github.com/spring-projects/spring-security/issues/15874) - OIDC logout not working for JPA/JDBC OAuth2AuthorizationService because DefaultSaml2AuthenticatedPrincipal does not implement equality [#&#8203;15346](https://github.com/spring-projects/spring-security/issues/15346) - Polish JdbcOneTimeTokenService [#&#8203;15997](https://github.com/spring-projects/spring-security/pull/15997) - relying-party-registration doesn't allow placeholders in xml [#&#8203;14645](https://github.com/spring-projects/spring-security/issues/14645) - Remove unnecessary parentheses and add static final field MockPortResolver#getServerPort [#&#8203;15875](https://github.com/spring-projects/spring-security/pull/15875) - Support ServerExchangeRejectedHandler `@Bean` [#&#8203;16063](https://github.com/spring-projects/spring-security/issues/16063) #### :beetle: Bug Fixes - An empty-string bearer token should result in an appropriate HTTP status code [#&#8203;16037](https://github.com/spring-projects/spring-security/issues/16037) - AuthorizeReturnObject AOT support should register proxied class as well [#&#8203;16106](https://github.com/spring-projects/spring-security/issues/16106) - Correct class name reference in WebFilterChainProxy JavaDoc [#&#8203;16004](https://github.com/spring-projects/spring-security/pull/16004) - Fix typo javadoc some classes [#&#8203;16022](https://github.com/spring-projects/spring-security/pull/16022) - Initialize OpenSAML in OpenSamlAssertingPartyMetadataRepository [#&#8203;16055](https://github.com/spring-projects/spring-security/pull/16055) - IpAddressMatcher null pointer exception [#&#8203;16104](https://github.com/spring-projects/spring-security/issues/16104) - OpenSamlAssertingPartyMetadataRepository should initialize OpenSAML [#&#8203;16042](https://github.com/spring-projects/spring-security/issues/16042) - Support ServerWebExchangeFirewall `@Bean` [#&#8203;15999](https://github.com/spring-projects/spring-security/issues/15999) - UniqueSecurityAnnotationScanner throws ConcurrentModificationException [#&#8203;15906](https://github.com/spring-projects/spring-security/issues/15906) #### :hammer: Dependency Upgrades - Bump ch.qos.logback:logback-classic from 1.5.11 to 1.5.12 [#&#8203;16005](https://github.com/spring-projects/spring-security/pull/16005) - Bump com.fasterxml.jackson:jackson-bom from 2.18.0 to 2.18.1 [#&#8203;16007](https://github.com/spring-projects/spring-security/pull/16007) - Bump com.webauthn4j:webauthn4j-core from 0.28.1.RELEASE to 0.28.2.RELEASE [#&#8203;16122](https://github.com/spring-projects/spring-security/pull/16122) - Bump io.freefair.gradle:aspectj-plugin from 8.10.2 to 8.11 [#&#8203;16123](https://github.com/spring-projects/spring-security/pull/16123) - Bump io.micrometer:micrometer-observation from 1.14.0 to 1.14.1 [#&#8203;16121](https://github.com/spring-projects/spring-security/pull/16121) - Bump io.projectreactor:reactor-bom from 2023.0.11 to 2023.0.12 [#&#8203;16079](https://github.com/spring-projects/spring-security/pull/16079) - Bump org-bouncycastle from 1.78.1 to 1.79 [#&#8203;16010](https://github.com/spring-projects/spring-security/pull/16010) - Bump org.hibernate.orm:hibernate-core from 6.6.1.Final to 6.6.2.Final [#&#8203;16048](https://github.com/spring-projects/spring-security/pull/16048) - Bump org.hsqldb:hsqldb from 2.7.3 to 2.7.4 [#&#8203;16028](https://github.com/spring-projects/spring-security/pull/16028) - Bump org.htmlunit:htmlunit from 4.5.0 to 4.6.0 [#&#8203;16044](https://github.com/spring-projects/spring-security/pull/16044) - Bump org.junit:junit-bom from 5.11.2 to 5.11.3 [#&#8203;15968](https://github.com/spring-projects/spring-security/pull/15968) - Bump org.seleniumhq.selenium:htmlunit3-driver from 4.25.0 to 4.26.0 [#&#8203;16043](https://github.com/spring-projects/spring-security/pull/16043) - Bump org.seleniumhq.selenium:selenium-java from 4.25.0 to 4.26.0 [#&#8203;16018](https://github.com/spring-projects/spring-security/pull/16018) - Bump org.springframework.data:spring-data-bom from 2024.0.5 to 2024.1.0 [#&#8203;16124](https://github.com/spring-projects/spring-security/pull/16124) - Bump org.springframework.ldap:spring-ldap-core from 3.2.7 to 3.2.8 [#&#8203;16097](https://github.com/spring-projects/spring-security/pull/16097) - Bump org.springframework:spring-framework-bom from 6.2.0-RC3 to 6.2.0 [#&#8203;16096](https://github.com/spring-projects/spring-security/pull/16096) #### :nut_and_bolt: Build Updates - Bump `@antora`/collector-extension from 1.0.0-beta.4 to 1.0.0-beta.5 in /docs [#&#8203;16115](https://github.com/spring-projects/spring-security/pull/16115) - Update Antora UI Spring to v0.4.17 [#&#8203;15929](https://github.com/spring-projects/spring-security/pull/15929) #### :heart: Contributors Thank you to all the contributors who worked on this release: [@&#8203;Chu3laMan](https://github.com/Chu3laMan), [@&#8203;Kehrlann](https://github.com/Kehrlann), [@&#8203;Limm-jk](https://github.com/Limm-jk), [@&#8203;dcolazin](https://github.com/dcolazin), [@&#8203;dependabot](https://github.com/dependabot)\[bot], [@&#8203;franticticktick](https://github.com/franticticktick), [@&#8203;github-actions](https://github.com/github-actions)\[bot], [@&#8203;gzhao9](https://github.com/gzhao9), [@&#8203;ig-jinwoo](https://github.com/ig-jinwoo), [@&#8203;jzheaux](https://github.com/jzheaux), [@&#8203;kse-music](https://github.com/kse-music), [@&#8203;ngocnhan-tran1996](https://github.com/ngocnhan-tran1996), and [@&#8203;nomoreFt](https://github.com/nomoreFt) ### [`v6.3.5`](https://github.com/spring-projects/spring-security/releases/tag/6.3.5) [Compare Source](https://github.com/spring-projects/spring-security/compare/6.3.4...6.3.5) #### :star: New Features - Support ServerExchangeRejectedHandler `@Bean` [#&#8203;16062](https://github.com/spring-projects/spring-security/issues/16062) - Supporting logout+jwt for back-channel logout with spring-webflux [#&#8203;15702](https://github.com/spring-projects/spring-security/issues/15702) #### :beetle: Bug Fixes - Align DelegatingAuthenticationConverter Constructors [#&#8203;15949](https://github.com/spring-projects/spring-security/pull/15949) - An empty-string bearer token should result in an appropriate HTTP status code [#&#8203;16036](https://github.com/spring-projects/spring-security/issues/16036) - IpAddressMatcher null pointer exception [#&#8203;15527](https://github.com/spring-projects/spring-security/issues/15527) - RequestMatcherDelegatingAuthorizationManager should be post-processable [#&#8203;15981](https://github.com/spring-projects/spring-security/issues/15981) - Support ServerWebExchangeFirewall `@Bean` [#&#8203;15991](https://github.com/spring-projects/spring-security/issues/15991) - Unhandled exception in CookieRequestCache results in 500 Internal Server Error [#&#8203;15986](https://github.com/spring-projects/spring-security/issues/15986) - Update logout.adoc: Fix Customizing Logout Success Example [#&#8203;15956](https://github.com/spring-projects/spring-security/pull/15956) #### :hammer: Dependency Upgrades - Bump ch.qos.logback:logback-classic from 1.5.11 to 1.5.12 [#&#8203;16006](https://github.com/spring-projects/spring-security/pull/16006) - Bump com.fasterxml.jackson:jackson-bom from 2.17.2 to 2.17.3 [#&#8203;16032](https://github.com/spring-projects/spring-security/pull/16032) - Bump io.micrometer:micrometer-observation from 1.12.12 to 1.12.13 [#&#8203;16126](https://github.com/spring-projects/spring-security/pull/16126) - Bump io.projectreactor:reactor-bom from 2023.0.11 to 2023.0.12 [#&#8203;16082](https://github.com/spring-projects/spring-security/pull/16082) - Bump org.hsqldb:hsqldb from 2.7.3 to 2.7.4 [#&#8203;16033](https://github.com/spring-projects/spring-security/pull/16033) - Bump org.springframework.data:spring-data-bom from 2024.0.5 to 2024.0.6 [#&#8203;16125](https://github.com/spring-projects/spring-security/pull/16125) - Bump org.springframework.ldap:spring-ldap-core from 3.2.7 to 3.2.8 [#&#8203;16102](https://github.com/spring-projects/spring-security/pull/16102) - Bump org.springframework:spring-framework-bom from 6.1.14 to 6.1.15 [#&#8203;16101](https://github.com/spring-projects/spring-security/pull/16101) #### :nut_and_bolt: Build Updates - Bump `@antora`/collector-extension from 1.0.0-beta.4 to 1.0.0-beta.5 in /docs [#&#8203;16117](https://github.com/spring-projects/spring-security/pull/16117) - Update Antora UI Spring to v0.4.17 [#&#8203;15930](https://github.com/spring-projects/spring-security/pull/15930) #### :heart: Contributors Thank you to all the contributors who worked on this release: [@&#8203;asimuleo](https://github.com/asimuleo), [@&#8203;dependabot](https://github.com/dependabot)\[bot], [@&#8203;github-actions](https://github.com/github-actions)\[bot], and [@&#8203;kse-music](https://github.com/kse-music) </details> --- ### Configuration 📅 **Schedule**: Branch creation - At any time (no schedule defined), Automerge - At any time (no schedule defined). 🚦 **Automerge**: Enabled. ♻ **Rebasing**: Whenever PR becomes conflicted, or you tick the rebase/retry checkbox. 🔕 **Ignore**: Close this PR and you won't be reminded about this update again. --- - [ ] <!-- rebase-check -->If you want to rebase/retry this PR, check this box --- This PR has been generated by [Renovate Bot](https://github.com/renovatebot/renovate). <!--renovate-debug:eyJjcmVhdGVkSW5WZXIiOiIzNy40MjAuMSIsInVwZGF0ZWRJblZlciI6IjM3LjQyMC4xIiwidGFyZ2V0QnJhbmNoIjoibWFpbiIsImxhYmVscyI6W119-->
Renovate Bot (Automatisiert) added 1 commit 2024-11-19 01:03:30 +01:00
Update dependency org.springframework.security:spring-security-crypto to v6.4.0
All checks were successful
Keycloak mailcow Build / Build und Bereitstellung (pull_request) Successful in 13s
Keycloak mailcow Build / Build und Bereitstellung (push) Successful in 15s
4e4192eb7b
Renovate Bot (Automatisiert) scheduled this pull request to auto merge when all checks succeed 2024-11-19 01:03:30 +01:00
Renovate Bot (Automatisiert) merged commit 4e4192eb7b into main 2024-11-19 01:05:42 +01:00
Sign in to join this conversation.
No description provided.