github spring-projects/spring-security 6.3.6

latest release: 6.4.2
one day ago

🪲 Bug Fixes

  • Always return current ClientRegistration in loadAuthorizedClient #16138
  • CI is not using the correct secret for Develocity #16262
  • Dark mode rendering issue with images on CSRF and Method Security pages #16175
  • Delay initialization AuthenticationProvider in Global Authentication #16050
  • Do not eagerly construct UserDetailsService bean in Global Authentication #16144
  • Documentation images should render clearly in both light and dark mode #16131
  • Mutate breaks functionality of StrictFirewallHttpHeaders with recently modified HttpHeaders#writabeHttpHeaders #16069
  • OidcBackChannelLogoutWebFilter error response is not a correct JSON #16229
  • Restore Servlet 5 Compatiblity for CookieCsrfTokenRepository #16219

🔨 Dependency Upgrades

  • Bump io.projectreactor:reactor-bom from 2023.0.12 to 2023.0.13 #16257
  • Bump org.gretty:gretty from 4.1.5 to 4.1.6 #16246
  • Bump org.jfrog.buildinfo:build-info-extractor-gradle from 4.33.22 to 4.33.23 #16179
  • Bump org.springframework.data:spring-data-bom from 2024.0.6 to 2024.0.7 #16289
  • Bump org.springframework.ldap:spring-ldap-core from 3.2.8 to 3.2.10 #16269
  • Bump org.springframework:spring-framework-bom from 6.1.15 to 6.1.16 #16272

🔩 Build Updates

  • Bump antora from 3.2.0-alpha.6 to 3.2.0-alpha.8 in /docs #16244
  • Update Antora UI Spring to v0.4.18 #16110

❤️ Contributors

Thank you to all the contributors who worked on this release:

@dependabot[bot], @github-actions[bot], and @kse-music

Don't miss a new spring-security release

NewReleases is sending notifications on new releases.