Spring Security 6.5.0-RC1 Is Out!

Releases | Josh Cummings | April 21, 2025 | ...

On behalf of the team and everyone who has contributed, I am pleased to announce the release candidate milestone for the final Spring Security 6 minor release.

Among a number of feature enhancements, there are some that we'd love your attention on as we prepare them for general availability:

Core

  • Complete Deprecation of ConfigAttribute, SecurityConfig, and other Access API components.

Specifically, please speak up if you are using any of the ACL Access components that were deprecated.

OAuth 2.0

SAML 2.0

  • Simplified SAML 2.0 Response validation (docs), Assertion validation (docs), and Authentication conversion (docs)
  • A RelayState-based Authentication Request Repository - #14793

Web

  • Further refinements to PathPatternRequestMatcher - #16765
  • Support for PathPatten in WebSocket - #16635, #16766
  • Improved integration between Spring MVC and @AuthorizeReturnObject - #16059

This is in addition to features released in previous milestones, which you can read more about in our What's New section of the reference.

Also, since this is the target release for migrating from 6.x to 7.x, please also begin reviewing the migration guide.

Please check the changelog for more details.

Project Page | GitHub | Issues | Documentation

Get the Spring newsletter

Stay connected with the Spring newsletter

Subscribe

Get ahead

VMware offers training and certification to turbo-charge your progress.

Learn more

Get support

Tanzu Spring offers support and binaries for OpenJDK™, Spring, and Apache Tomcat® in one simple subscription.

Learn more

Upcoming events

Check out all the upcoming events in the Spring community.

View all