Spring Boot 2.5.13 available now

Releases | Moritz Halbritter | April 21, 2022 | ...

On behalf of the team and everyone who has contributed, I'm happy to announce that Spring Boot 2.5.13 has been released and is now available from Maven Central.

This release includes 31 bug fixes, documentation improvements, and dependency upgrades. Thanks to all those who have contributed with issue reports and pull requests.

How can you help?

If you're interested in helping out, check out the "ideal for contribution" tag in the issue repository. If you have general questions, please ask on stackoverflow.com using the spring-boot tag or chat with the community on Gitter.

Project Page | GitHub | Issues | Documentation | Stack Overflow |

Spring Session 2021.2.0-RC1, 2021.1.3 and 2021.0.6 released

Releases | Eleftheria Stein-Kousathana | April 20, 2022 | ...

On behalf of the team, I’m pleased to announce the release of Spring Session 2021.2.0-RC1, 2021.1.3 and 2021.0.6. The 2021.2.0 release train is entering the RC phase. If you haven’t done so yet, please give it a try! The 2021.1.3 and 2021.0.6 releases deliver bug fixes and dependency upgrades. For your convenience, Spring Boot will pick up these artifacts with its upcoming releases.

The following modules were updated as part of 2021.2.0-RC1:

Spring for GraphQL 1.0 RC1 Released

Releases | Brian Clozel | April 20, 2022 | ...

On behalf of everyone involved, I'm pleased to announce the availability of the first and final release candidate of Spring for GraphQL 1.0. We're finally going to release a 1.0 version on May 17, the reference version for Spring Boot 2.7.0. We've shipped a few noteworthy changes and one important new feature in this release.

Note: The Spring for GraphqL Boot starter is up-to-date with the changes discussed in this post and Spring Boot 2.7.0-RC1 is scheduled to be released on Thursday this week.

GraphQL over RSocket

Spring for GraphQL started out with the HTTP and WebSocket transports - must haves in the GraphQL world. Our programming model allows adding others too, and our existing infrastructure pointed at another clear candidate: the RSocket protocol

This Week in Spring - April 19th, 2022

Engineering | Josh Long | April 19, 2022 | ...

Hi, Spring fans! Welcome to another installment of This Week in Spring! It's been quite the week since we last talked! I flew to Atlanta, GA, for my first in-person show since the pandemic - Devnexus 2022. I loved the experience! Hopefully, the only souvenirs I'll have are the amazing memories and not COVID. I loved to see so many smiling faces. Thanks so much for having me, Devnexus, and for running an amazing show. It was a privilege to return.

And now, without further ado, let's dive right into the roundup.

Spring Data 2021.2.0-RC1, 2021.1.4, and 2021.0.11 released

Releases | Christoph Strobl | April 19, 2022 | ...

The 2021.2.0 release train is entering the RC phase. If you haven't done so yet, please give it a try! The 2021.1.4 and 2021.0.11 service releases ship with mostly bug fixes and dependency upgrades. For your convenience those will be picked up by Spring Boot in the upcoming days.

To round things off, here are the links to the individual modules, changelogs, and documentation:

2021.2.0-RC1

Spring Security 5.7.0-RC1 released

Releases | Marcus Hert Da Coregio | April 18, 2022 | ...

On behalf of the community, I’m pleased to announce the release of Spring Security 5.7.0-RC1!

In addition to dependency upgrades, bug fixes, and minor enhancements, the release candidate contains a few noteworthy changes:

This release candidate is a good opportunity to give feedback before the actual GA release in mid-May. We look forward…

Spring Framework Data Binding Rules Vulnerability (CVE-2022-22968)

Engineering | Sam Brannen | April 13, 2022 | ...

Table of Contents

Overview

While investigating the Spring Framework RCE vulnerability CVE-2022-22965 and the suggested workaround, we realized that the disallowedFields configuration setting on WebDataBinder is not intuitive and is not clearly documented. We have fixed that but also decided to be on the safe side and announce a follow-up CVE, in order to ensure application developers are alerted and have a chance to review their configuration.

We have released Spring Framework 5.3.19 and 5.2.21 which contain the fix. Spring Boot 2.6.7 and 2.…

Spring Framework 5.3.19 and 5.2.21 available now

Releases | Stéphane Nicoll | April 13, 2022 | ...

On behalf of the team and everyone who has contributed, I am pleased to announce that Spring Framework 5.3.19 and 5.2.21 are available now.

Spring Framework 5.3.19 includes 12 fixes and improvements. Spring Framework 5.2.21 includes 5 selected fixes and improvements.

In addition, Spring Framework 5.3.19 and 5.2.21 include a fix for CVE-2022-22968: Spring Framework Data Binding Rules Vulnerability and are recommended upgrades for all Spring production scenarios.

Project Page | GitHub | Issues | Documentation

Get the Spring newsletter

Thank you for your interest. Someone will get back to you shortly.

Get ahead

VMware offers training and certification to turbo-charge your progress.

Learn more

Get support

Tanzu Spring Runtime offers support and binaries for OpenJDK™, Spring, and Apache Tomcat® in one simple subscription.

Learn more

Upcoming events

Check out all the upcoming events in the Spring community.

View all