Josh Cummings

Josh Cummings

Spring Security committer | Herriman, Utah

Josh has been a software engineer for over 15 years building enterprise applications across multiple industries. He has long been passionate about application security and loves opportunities to mentor and to learn from others about security awareness. When Josh isn't hacking away at code, he is either running, playing basketball, camping, or reading a Brandon Sanderson novel.
Blog posts by Josh Cummings

Spring Security 5.7.3 and 5.6.7 available now

Releases | August 15, 2022 | ...

On behalf of the team and everyone who has contributed, I am pleased to announce that Spring Security 5.7.3 and 5.6.7 are available now. In both cases the releases are largely composed of dependency upgrades and minor fixes.

To learn more, please visit the 5.7.3 and 5.6.7 release summaries.

Spring Security 5.8.0-M1 and 6.0.0-M6 are released

Engineering | July 18, 2022 | ...

On behalf of the team and everyone who has contributed, I am pleased to announce that Spring Security 5.8.0-M1 and 6.0.0-M6 are available now.

This release includes dependency upgrades, bug fixes, and enhancements. Here are a few noteworthy changes:

See the 5.8.0-M1 and 6.0.0-M6 release notes for more details.

Project Site | Reference | Help

Spring Security 5.5.0-RC1 released

Releases | April 12, 2021 | ...

On behalf of the community, I’m pleased to announce the release of Spring Security 5.5.0-RC1!

In addition to dependency upgrades, bug fixes, and minor enhancements, the release candidate contains a few noteworthy changes:

  • JWT client authentication support for OAuth 2.0 clients

  • JWT bearer authorization grant support for OAuth 2.0 clients

  • AuthorizationManager, a new authorization API for filter security

  • Kotlin coroutine support for reactive method security

  • OpenSAML 4 support

This release candidate is a good opportunity to give feedback before the actual GA release in mid-May. We look…

Spring Security SAML Extensions 1.x EOL on October 6, 2021

Releases | September 22, 2020 | ...

With the recent release of Spring Security 5.4, we’d like to announce that maintenance for Spring Security SAML Extensions 1.x will end on 6 October 2021.

SAML 2.0 support has been added to the core Spring Security framework over the last three minor releases. There are two main reasons for this.

First, the extension project is based on a version of OpenSAML that the OpenSAML team no longer supports. This version has known CVEs that make it unsafe for use in a production system.

Second, moving the support to the core Spring Security framework allowed us to simplify the API, use the latest OpenSAML, and add long-requested support for features like multi-tenancy and Spring Boot integration

Get ahead

VMware offers training and certification to turbo-charge your progress.

Learn more

Get support

Spring Runtime offers support and binaries for OpenJDK™, Spring, and Apache Tomcat® in one simple subscription.

Learn more

Upcoming events

Check out all the upcoming events in the Spring community.

View all