Spring Security 5.2.0.M3 Released

Releases | Eleftheria Stein-Kousathana | June 17, 2019 | ...

On behalf of the community, I’m pleased to announce the release of Spring Security 5.2.0.M3! You can find the complete details in the changelog and the highlights below:

OAuth 2.0

gh-6727 - Support for Multi-tenancy in Reactive Resource Server
gh-6798 - Support for custom parameters in Opaque Token
gh-6239 - Finer variables for OAuth2 redirectUriTemplate expansion
gh-6863 - OAuth2 login has configurable authentication success handler
gh-6832 & gh-6849 - JWT and opaque token have configurable authentication manager
gh-6634 - Support for mock JWT in tests

Similar to other request post processors, jwt() can be used to establish a SecurityContext with a JwtAuthenticationToken

Spring Data Moore RC1 and Lovelace SR9 released

Releases | Christoph Strobl | June 17, 2019 | ...

On behalf of the team I am pleased to announce Spring Data releases Moore RC1 and Lovelace SR9. The new bits build on the most recent Spring Framework releases and will be picked up by Spring Boot 2.2 M4 and 2.1.6 respectively.

Notable new features amongst others are:

  • An EntityCallback API for modifying entities before convert or save.
  • Multiple OUT parameters in the stored procedure support of Spring Data JPA.
  • Declarative aggregations in Spring Data MongoDB.
  • Enhanced SSL support and dynamic client port configuration for Gemfire and Apache Geode.

Please find a high-level overview of what has been added in our release wiki. As always, we’re…

Spring Session for Apache Geode & Pivotal GemFire 2.1.4.RELEASE & 2.2.0.M2 Available

Releases | John Blum | June 17, 2019 | ...

On behalf of the Spring and Apache Geode communities, it is my pleasure to announce the release of Spring Session for Apache Geode and Pivotal GemFire (SSDG) 2.1.4.RELEASE and 2.2.0.M2 releases.

Both SSDG 2.1.4.RELEASE and 2.2.0.M2 now support the ability to turn off client subscriptions. No longer does SSDG require client subscriptions to be enabled to use either Apache Geode or Pivotal GemFire to manage your HTTP Session state. However, if client subscriptions are not explicitly enabled, then the client will no longer receive notifications of Session events that may have originated from…

Spring Cloud Finchley SR4 Released

Releases | Marcin Grzejszczak | June 14, 2019 | ...

On behalf of the community, I am pleased to announce that the Service Release 4 (SR4) of the Spring Cloud Finchley Release Train is available today. The release can be found in Maven Central. You can check out the Finchley release notes for more information.

Notable Changes in the Finchley Release Train

Spring Cloud Commons

Bug Fixes

Spring Cloud Vault

Bug Fixes

Spring Cloud Config

Bug Fixes

Spring Cloud Gateway

Bug Fixes

Spring Cloud Netflix

Bug Fixes

Spring Cloud Sleuth

Bug Fixes

Spring Cloud Consul

Bug Fixes

Spring Cloud Contract

Bug Fixes

The following modules were updated as part of…

Spring Framework 5.2.0.M3 and 5.1.8 available now

Releases | Stéphane Nicoll | June 13, 2019 | ...

On behalf of the team and everyone who has contributed, I am pleased to announce that Spring Framework 5.2.0.M3 and 5.1.8 are available now.

The third milestone of Spring Framework 5.2 includes 50 fixes and improvements while Spring Framework 5.1.8 includes 31 fixes and selected improvements.

If you want to give the milestone a try, you can boostrap a new application on start.spring.io once Spring Boot 2.2.0.M4 is released early next week.

Project Page | GitHub | Issues | Documentation

Java CFEnv 1.1.0.RC1 Released

Releases | Mark Pollack | June 12, 2019 | ...


On behalf of the community I am happy to announce the release of Java CFEnv 1.1 RC1.

The RC1 release adds the following functionality:

  • Checks the classpath to correctly determine setting of MySQL or MariaDB driver class name.

  • When using the Boot support, an exception is thrown if the Spring Cloud Connector library is on the classpath. This applies only for the following services: DataSource, RabbitMQ, Cassandra, MongoDB, and Redis. The exception message indicates to set the environment variable JBP_CONFIG_SPRING_AUTO_RECONFIGURATION '{enabled: false}'

  • Support for Boot 1.5.x by copying a logging utility class into the project.

Announcing nohttp

Engineering | Rob Winch | June 10, 2019 | ...

I’m pleased to announce the nohttp project, which lets users find, replace, and prevent the usage of http://.


Today, Jonathan Leitschuh published a blog titled Want to take over the Java ecosystem? All you need is a MITM!. The blog demonstrates that hundreds of Java libraries are downloading dependencies over HTTP. This opens the projects up to potential MITM (man in the middle) attacks.

Unfortunately, there were multiple Spring projects that were using HTTP to download dependencies. Fortunately, we uncovered no signs of a successful MITM attack. We have also addressed the issue to…

This Week in Spring - June 11th, 2019

Engineering | Josh Long | June 10, 2019 | ...

Hi Spring fans! Can you believe it? We're already almost halfway through June! Summer's nearly here! It's 97 Fahrenheit / 37 Celsius in San Francisco! That's nuts! I'm glad I'm in beautiful Amsterdam and Eindhoven, NL, beating the heat, though. What a privilege. We've got a busy week, as always, to get to so let's get to it!

