Spring Integration Zip 1.0.4 & CVE-2021-22114

Releases | Artem Bilan | March 01, 2021 | ...

Dear Spring community,

On behalf of the team and everyone who contributed, it is my pleasure to announce 1.0.4.RELEASE version for Spring Integration Zip extension.

CVE-2021-22114

The UnZipTransformer doesn’t cover all the cases for Zip Slip Vulnerability and some particular zip entry names may still end up outside of working directory.

The updated fix has been released in the spring-integration-zip-1.0.4.RELEASE version together with some other bug fixes and improvements. We also have published a new advisory for CVE-2021-22114.

Credit: Trung Pham, Viettel Cyber Security.

Everybody who’s…

Spring Tips: Spring Cloud Gateway (Redux)

Engineering | Josh Long | February 24, 2021 | ...

Hi, Spring fans! In this installment of Spring Tips, I revisit Spring Cloud Gateway.

Here's what's inside:

Intro

11:12​ Have your cake and Eat it too with an API Gateway

Basics

00:11:37​ Get to Know Your New Gateway 00:21:18​ The Observable Gateway
00:22:39​ Meet The Supporting Characters
00:24:30​ Reactive Data For The Demo
00:28:10​ A Reactive WebSocket Endpoint 00:31:00​ Reactive HTTP Endpoint

Behind the Source with Spring Cloud co-founder, lead, and Spring Cloud Gateway creator Spencer Gibb

00:33:00​ Spencer Gibb

Service Discovery

37:59​ Introducing Spring Cloud Netflix Eureka 40:4…

This Week in Spring - February 23rd, 2021

Engineering | Josh Long | February 24, 2021 | ...

Hi, Spring fans! Welcome to another installment of This Week in Spring! This week's been exciting and only going to get more exciting as the days carry on.

Tomorrow, the 24th of February, I'll be participating in a panel with Angie Jones, Daniel Bryant, Stefania Chaplin, and Jonathan Harris on how to debug and fix issues so that it doesn't block production.

Tomorrow, I'll_also_ be streaming on Twitch.tv around noon PST. Join us!

Alright, without any further ado, this week's roundup! Enjoy!

Spring Initializr 0.10.0 available now

Releases | Stéphane Nicoll | February 19, 2021 | ...

On behalf of the team and everyone who has contributed, I’m happy to announce that Spring Initializr 0.10.0 has been released and is now available from Maven Central.

This release includes 27 fixes, improvements and dependency upgrades. Thanks to all those who have contributed with issue reports and pull requests.

For full upgrade instructions and new and noteworthy features please see the release notes.

GitHub | Issues | Documentation | Stack Overflow | Gitter

Spring HATEOAS 1.3 M2 released

Releases | Oliver Drotbohm | February 19, 2021 | ...

For all users building hypermedia based API, I’d like to announce that we shipped Spring HATEOAS 1.3 M2. We ship two major themes with the release:

Spring Boot 2.5.0-M2 available now

Releases | Phil Webb | February 19, 2021 | ...

Continuing our monthly milestone release cadence, I am pleased to announce that the second milestone of Spring Boot 2.5 has been released and is available from our milestone repository. This release adds a number of new features and bug fixes.

Highlights of this milestone include:

  • Layered WARs support for use with Docker
  • Custom Buildpack Builder Support
  • Jetty 10 Support
  • Early Support for Gradle 7

We've also made some significant behind-the-scenes changes to do with the way that schema.sql and data.sql files are processed. If you use those features, please try the milestone and let us know if…

Spring Boot 2.4.3 is now available

Releases | Andy Wilkinson | February 18, 2021 | ...

On behalf of the team and everyone who has contributed, I'm happy to announce that Spring Boot 2.4.3 has been released and is now available from Maven Central.

This release includes 75 bug fixes, documentation improvements, and dependency upgrades. Thanks to all those who have contributed with issue reports and pull requests.

How can you help?

If you're interested in helping out, check out the "ideal for contribution" tag in the issue repository. If you have general questions, please ask on stackoverflow.com using the spring-boot tag or chat with the community on Gitter.

Project Page | GitHub | Issues | Documentation | Stack Overflow |

Get the Spring newsletter

Thank you for your interest. Someone will get back to you shortly.

Get ahead

VMware offers training and certification to turbo-charge your progress.

Learn more

Get support

Tanzu Spring Runtime offers support and binaries for OpenJDK™, Spring, and Apache Tomcat® in one simple subscription.

Learn more

Upcoming events

Check out all the upcoming events in the Spring community.

View all