github quarkusio/quarkus 3.27.6

latest release: 3.40.1
2 hours ago

Complete changelog

  • #50365 - Bump keycloak to 26.4.0 and keycloak-client to 26.0.7
  • #50404 - Application with quarkus-keycloak-admin-rest-client fails to compile after recent Keycloak bump
  • #50405 - Initialize org.keycloak.common.util.SecretGenerator at runtime for Keycloak admin client
  • #51596 - Bump org.mariadb.jdbc:mariadb-java-client from 3.5.6 to 3.5.7
  • #53836 - Bump org.mariadb.jdbc:mariadb-java-client from 3.5.7 to 3.5.8
  • #54872 - Bump org.mariadb.jdbc:mariadb-java-client from 3.5.8 to 3.5.9
  • #55171 - [3.27] Upgrade to Keycloak 26.0.10
  • #55288 - [3.x] OpenShift Client native integration test fails after #55242
  • #55301 - [3.27] Bump the hibernate group with 7 updates
  • #55319 - Fix native image build failure caused by Netty's SelfSignedCertificate
  • #55380 - Harden remote dev mode against path traversal and unsafe deserialization
  • #55403 - Fix bad link syntax and update cross-document references to use xref
  • #55531 - [3.27] Update to Vert.x 4.5.30 and Netty 4.1.136.Final
  • #55552 - [3.27] Upgrade to Jackson 2.21.5
  • #55557 - [3.27] Bump to Vert.x 4.5.31
  • #55568 - Update sync script to handle Qute site
  • #55622 - [3.27] Bump sshd to 2.19.0
  • #55671 - [3.27] Make some OIDC authentication failure messages more verbose
  • #55672 - [3.27] Backport changes related to raising level of some of OIDC log messages
  • #55683 - Bump at.yawk.lz4:lz4-java from 1.10.1 to 1.11.1 in /bom/application
  • #55887 - OIDC: malformed bearer token (empty or dots-only) causes NoSuchElementException in OidcCommonUtils.getJwtContentPart -> HTTP 500 instead of 401
  • #55905 - Guard against a JWT with no parts in OidcCommonUtils and OidcUtils
  • #55913 - [3.x] Bump to Vert.x 4.5.32 and Netty 4.1.137.Final
  • #55915 - Bump org.jsoup:jsoup from 1.15.3 to 1.23.1 in /core/processor
  • #55969 - [3.27] Bump the hibernate group with 7 updates
  • #56055 - Manage jsoup version in the bom
  • #56093 - Some JSoup-related cleanup
  • #56114 - [3.27] Set a default GraphQL query depth limit of 10 to prevent DoS
  • #56184 - Add missing include::_attributes.adoc[] to init-tasks and build-analytics guides
  • #56191 - Confine Dev UI workspace JSON-RPC operations to the project root
  • #56311 - [3.27] Fix reading headers in Spring Web - Quarkus REST
  • #56314 - Bump org.jsoup:jsoup from 1.23.1 to 1.23.2
  • #56322 - [3.27] Use composite key for token introspection and userinfo cache
  • #56334 - [3.27] Upgrade SmallRye GraphQL to 2.14.3
  • #56338 - [3.27] Server-Side Template Injection (SSTI) vulnerability in ReflectionValueResolver of the Quarkus Qute template engine
  • #56345 - [3.27] Upgrade bouncycastle version to 1.85
  • #56363 - [3.27] Upgrade RESTEasy to 6.2.18.Final
  • #56369 - [3.27] Manage projectreactor in the bom, update to 3.8.7
  • #56532 - Manage zstd-jni in the bom
  • #56570 - [3.27] Bump to Vert.x 4.5.34
  • #56632 - Bump zstd-jni to 1.5.7-16
  • #56747 - The default GraphQL query depth of limit 10 prevents graphql-ui from running its introspection query
  • #56748 - Bump the default GraphQL query depth limit to 20
  • #56753 - [3.27] Bump Jackson to 2.21.6
  • #56760 - [3.27] Explicit update to Netty 4.1.138.Final
  • #56787 - Bump to BouncyCastle 1.86.1
  • #56799 - [3.27] Bump freemarker to 2.3.35
  • #56819 - [3.27] SmallRye Fault Tolerance: bump to 6.9.4
  • #56833 - [3.27] Qute: EvalSectionHelper and StrEvalNamespaceResolver fixes
  • #56847 - [3.27] Upgrade RESTEasy to 6.2.19.Final
  • #56855 - [3.27] Upgrade to Hibernate 7.1.36.Final
  • #56859 - [3.27] WebSockets Next: add max-pending-messages back-pressure
  • #56863 - [3.27] Fix path normalization bypass on wildcard routes (matrix-param + dot-segment)
  • #56869 - [3.27] : Bump smallrye-jwt version to 4.6.4
  • #56888 - [3.27] Upgrade to Elytron 2.6.10.SP1
  • #56914 - [3.27] Bump to BouncyCastle 1.86.1

Don't miss a new quarkus release

NewReleases is sending notifications on new releases.