spring-projects/spring-security
 Watch   
 Star   
 Fork   
9 days ago
spring-security

7.2.0-M1

⭐ New Features

  • Add Implicit CorsConfigurationSource/PreFlightRequestHandler Detection to <cors> XML Namespace #19542
  • Add Release Announcement Workflows #19573
  • Validate account status in OneTimeTokenAuthenticationProvider #17656
  • Fix Broken DefaultLoginPageGeneratingFilter Javadoc Link #19252
  • Remove BeanResolver Null Checks #19209
  • Remove Unnecessary AuthorizationDecision Cast #19283
  • Update One-Time Token Docs for Renamed APIs #19274

🪲 Bug Fixes

  • Find mixed-case names in InMemoryUserDetailsManager#changePassword #19540
  • Correct validation logic in CasAuthenticationToken #19372
  • Differentiate Forwarded and X-Forwarded headers in proxy docs #19477
  • Fix OAuth2PushedAuthorizationRequestUri parsing #19445
  • Update JavaDoc Links in Reference #19199
  • Validate Parameter in setPostAuthenticationChecks #19277

🔨 Dependency Upgrades

  • Bump ch.qos.logback:logback-classic from 1.6.1 to 1.6.2 #19555
  • Bump ch.qos.logback:logback-classic from 1.6.2 to 1.6.3 #19559
  • Bump com.fasterxml.jackson:jackson-bom from 2.22.1 to 2.22.2 #19565
  • Bump com.nimbusds:oauth2-oidc-sdk from 11.38.1 to 11.38.2 #19462
  • Bump org.apache.httpcomponents.client5:httpclient5 from 5.6.3 to 5.6.4 #19537
  • Bump org.seleniumhq.selenium:htmlunit3-driver from 4.43.0 to 4.46.0 #19451
  • Bump org.seleniumhq.selenium:selenium-java from 4.43.0 to 4.46.0 #19440

FAILURE: Build failed with an exception.

  • Bump tools.jackson:jackson-bom from 3.2.1 to 3.2.2 #19560

🔩 Build Updates

  • Disable CORS Tests Relying on HandlerMappingIntrospector #19543
  • Disable Lowercase HTTP Method Firewall Test #19541
  • Prepare for Spring Security 7.2 #19527
  • Suppress removal Warnings on RestOperations/RestTemplate Usage #19544

❤️ Contributors

Thank you to all the contributors who worked on this release:

@therepanic

9 days ago
spring-security

7.1.1

⭐ New Features

  • Fix Broken DefaultLoginPageGeneratingFilter Javadoc Link #19252
  • Remove BeanResolver Null Checks #19209
  • Remove Unnecessary AuthorizationDecision Cast #19283
  • Update One-Time Token Docs for Renamed APIs #19274

🪲 Bug Fixes

  • Correct validation logic in CasAuthenticationToken #19372
  • Differentiate Forwarded and X-Forwarded headers in proxy docs #19477
  • Find mixed-case names in InMemoryUserDetailsManager#changePassword #19539
  • Fix OAuth2PushedAuthorizationRequestUri parsing #19445
  • Update JavaDoc Links in Reference #19199
  • Validate Parameter in setPostAuthenticationChecks #19277

🔨 Dependency Upgrades

  • Bump @springio/antora-extensions from 1.14.12 to 1.14.13 in /docs #19503
  • Bump actions/checkout from 6.0.3 to 7.0.0 #19351
  • Bump actions/checkout from 7.0.0 to 7.0.1 #19464
  • Bump actions/setup-java from 5.2.0 to 5.3.0 #19352
  • Bump actions/setup-java from 5.3.0 to 5.4.0 #19380
  • Bump actions/setup-java from 5.4.0 to 5.5.0 #19430
  • Bump actions/setup-java from 5.5.0 to 5.6.0 #19453
  • Bump actions/setup-java from 5.6.0 to 5.7.0 #19501
  • Bump antora from 3.2.0-alpha.12 to 3.2.0-rc.2 in /docs #19385
  • Bump ch.qos.logback:logback-classic from 1.5.34 to 1.5.35 #19374
  • Bump ch.qos.logback:logback-classic from 1.5.35 to 1.5.36 #19389
  • Bump ch.qos.logback:logback-classic from 1.5.36 to 1.5.37 #19396
  • Bump ch.qos.logback:logback-classic from 1.5.37 to 1.5.38 #19431
  • Bump ch.qos.logback:logback-classic from 1.5.38 to 1.6.0 #19467
  • Bump ch.qos.logback:logback-classic from 1.6.0 to 1.6.1 #19476
  • Bump ch.qos.logback:logback-classic from 1.6.1 to 1.6.2 #19556
  • Bump ch.qos.logback:logback-classic from 1.6.2 to 1.6.3 #19564
  • Bump com.fasterxml.jackson:jackson-bom from 2.22.0 to 2.22.1 #19419
  • Bump com.fasterxml.jackson:jackson-bom from 2.22.1 to 2.22.2 #19566
  • Bump com.nimbusds:oauth2-oidc-sdk from 11.37.2 to 11.38.1 #19439
  • Bump com.nimbusds:oauth2-oidc-sdk from 11.38.1 to 11.38.2 #19525
  • Bump com.unboundid:unboundid-ldapsdk from 7.0.4 to 7.0.5 #19322
  • Bump com.webauthn4j:webauthn4j-core from 0.31.6.RELEASE to 0.31.7.RELEASE #19313
  • Bump com.webauthn4j:webauthn4j-core from 0.31.7.RELEASE to 0.31.8.RELEASE #19409
  • Bump com.webauthn4j:webauthn4j-core from 0.31.8.RELEASE to 0.31.9.RELEASE #19496
  • Bump gradle-wrapper from 9.5.1 to 9.6.0 #19360
  • Bump gradle-wrapper from 9.6.0 to 9.6.1 #19393
  • Bump gradle-wrapper from 9.6.1 to 9.7.0 #19516
  • Bump io.spring.nullability:io.spring.nullability.gradle.plugin from 0.0.13 to 0.0.14 #19378
  • Bump org-bouncycastle from 1.84 to 1.85 #19437
  • Bump org-jetbrains-kotlin from 2.4.0 to 2.4.10 #19447
  • Bump org-opensaml5 from 5.2.2 to 5.2.3 #19358
  • Bump org.apache.httpcomponents.client5:httpclient5 from 5.6.1 to 5.6.2 #19401
  • Bump org.apache.httpcomponents.client5:httpclient5 from 5.6.2 to 5.6.3 #19495
  • Bump org.apache.httpcomponents.client5:httpclient5 from 5.6.3 to 5.6.4 #19538
  • Bump org.apache.kerby:kerb-simplekdc from 2.1.1 to 2.1.2 #19387
  • Bump org.hibernate.orm:hibernate-core from 7.4.0.Final to 7.4.1.Final #19312
  • Bump org.hibernate.orm:hibernate-core from 7.4.1.Final to 7.4.2.Final #19364
  • Bump org.hibernate.orm:hibernate-core from 7.4.2.Final to 7.4.3.Final #19402
  • Bump org.hibernate.orm:hibernate-core from 7.4.3.Final to 7.4.4.Final #19416
  • Bump org.hibernate.orm:hibernate-core from 7.4.4.Final to 7.4.5.Final #19443
  • Bump org.junit:junit-bom from 6.1.0 to 6.1.1 #19395
  • Bump org.junit:junit-bom from 6.1.1 to 6.1.2 #19442
  • Bump org.junit:junit-bom from 6.1.2 to 6.1.3 #19524
  • Bump org.junit:junit-bom from 6.1.2 to 6.1.3 #19519
  • Bump org.seleniumhq.selenium:htmlunit3-driver from 4.43.0 to 4.45.0 #19365
  • Bump org.seleniumhq.selenium:selenium-java from 4.43.0 to 4.45.0 #19344
  • Bump tools.jackson:jackson-bom from 3.2.0 to 3.2.1 #19438
  • Bump tools.jackson:jackson-bom from 3.2.1 to 3.2.2 #19562
  • Release 7.1.1 #19310
  • Upgrade to Micrometer 1.17.1 #19489
  • Upgrade to Reactor 2025.0.7 #19488
  • Upgrade to Spring Framework 7.0.9 #19487
  • Upgrade to Spring LDAP 4.1.1 #19491
9 days ago
spring-security

7.0.7

⭐ New Features

  • Fix Broken DefaultLoginPageGeneratingFilter Javadoc Link #19252
  • Remove BeanResolver Null Checks #19209
  • Remove Unnecessary AuthorizationDecision Cast #19283
  • Update One-Time Token Docs for Renamed APIs #19274

🪲 Bug Fixes

  • Correct validation logic in CasAuthenticationToken #19372
  • Differentiate Forwarded and X-Forwarded headers in proxy docs #19477
  • Find mixed-case usernames in InMemoryUserDetailsManager#changePassword #19337
  • Fix OAuth2PushedAuthorizationRequestUri parsing #19445
  • Update JavaDoc Links in Reference #19199
  • Validate Parameter in setPostAuthenticationChecks #19277

🔨 Dependency Upgrades

  • Bump @springio/antora-extensions from 1.14.12 to 1.14.13 in /docs #19504
  • Bump actions/checkout from 6.0.3 to 7.0.1 #19466
  • Bump actions/setup-java from 5.2.0 to 5.7.0 #19505
  • Bump antora from 3.2.0-alpha.12 to 3.2.0-rc.2 in /docs #19381
  • Bump ch.qos.logback:logback-classic from 1.5.34 to 1.5.38 #19433
  • Bump com.unboundid:unboundid-ldapsdk from 7.0.4 to 7.0.5 #19323
  • Bump org.apache.kerby:kerb-simplekdc from 2.1.1 to 2.1.2 #19391

❤️ Contributors

Thank you to all the contributors who worked on this release:

@ArzMeow, @big-cir, @junhyeong9812, @jyx-07, @ngocnhan-tran1996, @skdas20, @snowykte0426, and @therepanic

2026-06-10 00:05:12
spring-security

7.1.0

🪲 Bug Fixes

  • Opaque token introspectors should not allow empty credentials #19201

🔨 Dependency Upgrades

  • Bump @springio/antora-extensions from 1.14.11 to 1.14.12 in /docs #19235
  • Bump actions/checkout from 6.0.2 to 6.0.3 #19271
  • Bump antora from 3.2.0-alpha.11 to 3.2.0-alpha.12 in /docs #19181
  • Bump ch.qos.logback:logback-classic from 1.5.32 to 1.5.33 #19228
  • Bump ch.qos.logback:logback-classic from 1.5.33 to 1.5.34 #19268
  • Bump com.fasterxml.jackson:jackson-bom from 2.21.2 to 2.21.3 #19133
  • Bump com.fasterxml.jackson:jackson-bom from 2.21.3 to 2.22.0 #19246
  • Bump com.google.code.gson:gson from 2.13.2 to 2.14.0 #19125
  • Bump com.nimbusds:oauth2-oidc-sdk from 11.37 to 11.37.1 #19157
  • Bump com.nimbusds:oauth2-oidc-sdk from 11.37 to 11.37.2 #19195
  • Bump com.webauthn4j:webauthn4j-core from 0.31.3.RELEASE to 0.31.5.RELEASE #19148
  • Bump com.webauthn4j:webauthn4j-core from 0.31.5.RELEASE to 0.31.6.RELEASE #19263
  • Bump gradle-wrapper from 9.4.1 to 9.5.0 #19135
  • Bump gradle-wrapper from 9.5.0 to 9.5.1 #19171
  • Bump io-micrometer from 1.16.5 to 1.17.0 #19287
  • Bump io.mockk:mockk from 1.14.9 to 1.14.11 #19244
  • Bump io.projectreactor:reactor-bom from 2025.0.5 to 2025.0.6 #19296
  • Bump org-jetbrains-kotlin from 2.3.20 to 2.3.21 #19126
  • Bump org-jetbrains-kotlin from 2.3.21 to 2.4.0 #19264
  • Bump org-opensaml5 from 5.2.1 to 5.2.2 #19176
  • Bump org.apache.maven:maven-resolver-provider from 3.9.15 to 3.9.16 #19190
  • Bump org.apereo.cas.client:cas-client-core from 4.1.0 to 4.1.1 #19200
  • Bump org.hibernate.orm:hibernate-core from 7.3.1.Final to 7.3.2.Final #19119
  • Bump org.hibernate.orm:hibernate-core from 7.3.2.Final to 7.3.3.Final #19149
  • Bump org.hibernate.orm:hibernate-core from 7.3.3.Final to 7.3.4.Final #19165
  • Bump org.hibernate.orm:hibernate-core from 7.3.4.Final to 7.3.5.Final #19191
  • Bump org.hibernate.orm:hibernate-core from 7.3.5.Final to 7.3.6.Final #19211
  • Bump org.hibernate.orm:hibernate-core from 7.3.6.Final to 7.4.0.Final #19226
  • Bump org.jetbrains.kotlinx:kotlinx-coroutines-bom from 1.10.2 to 1.11.0 #19166
  • Bump org.junit:junit-bom from 6.0.3 to 6.1.0 #19197
  • Bump org.slf4j:slf4j-api from 2.0.17 to 2.0.18 #19169
  • Bump org.springframework.data:spring-data-bom from 2025.1.5 to 2025.1.6 #19290
  • Bump org.springframework.ldap:spring-ldap-core from 4.0.3 to 4.1.0 #19291
  • Bump org.springframework:spring-framework-bom from 7.0.7 to 7.0.8 #19285
  • Bump spring-io/spring-release-actions from 0.0.4 to 0.0.5 #19179
  • Bump tools.jackson:jackson-bom from 3.1.2 to 3.1.3 #19147
  • Bump tools.jackson:jackson-bom from 3.1.3 to 3.1.4 #19245
  • Bump tools.jackson:jackson-bom from 3.1.4 to 3.2.0 #19286
  • Update to spring-data-bom 2026.0.0 #19303

🔩 Build Updates

2026-06-09 23:31:10
spring-security

7.0.6

🪲 Bug Fixes

  • FormPostRedirectStrategy should not emit percent-encoded values into hidden form inputs #19137
  • AbstractAuthenticationFilterConfigurer should not automatically pick up servlet path #19128
  • Principal Extractor should select the left-most RDN attribute value #19254

🔨 Dependency Upgrades

  • Bump antora from 3.2.0-alpha.11 to 3.2.0-alpha.12 in /docs #19184
  • Bump ch.qos.logback:logback-classic from 1.5.32 to 1.5.34 #19266
  • Bump com.webauthn4j:webauthn4j-core from 0.31.3.RELEASE to 0.31.5.RELEASE #19151
  • Bump com.webauthn4j:webauthn4j-core from 0.31.5.RELEASE to 0.31.6.RELEASE #19265
  • Bump gradle-wrapper from 8.14.4 to 8.14.5 #19160
  • Bump io-micrometer from 1.16.5 to 1.16.6 #19292
  • Bump io.mockk:mockk from 1.14.9 to 1.14.11 #19247
  • Bump io.projectreactor:reactor-bom from 2025.0.5 to 2025.0.6 #19298
  • Bump org-bouncycastle from 1.80 to 1.80.2 #19193
  • Bump org.apache.maven:maven-resolver-provider from 3.9.15 to 3.9.16 #19192
  • Bump org.slf4j:slf4j-api from 2.0.17 to 2.0.18 #19174
  • Bump org.springframework.data:spring-data-bom from 2025.1.5 to 2025.1.6 #19294
  • Bump org.springframework.ldap:spring-ldap-core from 4.0.3 to 4.0.4 #19289
  • Bump org.springframework:spring-framework-bom from 7.0.7 to 7.0.8 #19288
  • Bump spring-io/spring-release-actions from 0.0.4 to 0.0.5 #19182
  • Update to Micrometer 1.16.5 #19225

🔩 Build Updates

2026-06-09 23:25:02
spring-security

6.5.11

🪲 Bug Fixes

  • FormPostRedirectStrategy should not emit percent-encoded values into hidden form inputs #19136

🔨 Dependency Upgrades

  • Bump antora from 3.2.0-alpha.11 to 3.2.0-alpha.12 in /docs #19185
  • Bump ch.qos.logback:logback-classic from 1.5.32 to 1.5.34 #19299
  • Bump com.fasterxml.jackson:jackson-bom from 2.18.6 to 2.18.7 #19129
  • Bump com.fasterxml.jackson:jackson-bom from 2.18.7 to 2.18.8 #19297
  • Bump gradle-wrapper from 8.14.4 to 8.14.5 #19159
  • Bump org-bouncycastle from 1.80 to 1.80.2 #19204
  • Bump org.apache.maven:maven-resolver-provider from 3.9.15 to 3.9.16 #19205
  • Bump org.hibernate.orm:hibernate-core from 6.6.49.Final to 6.6.50.Final #19150
  • Bump org.hibernate.orm:hibernate-core from 6.6.50.Final to 6.6.51.Final #19213
  • Bump org.hibernate.orm:hibernate-core from 6.6.51.Final to 6.6.53.Final #19300
  • Bump org.slf4j:slf4j-api from 2.0.17 to 2.0.18 #19173
  • Bump org.springframework:spring-framework-bom from 6.2.18 to 6.2.19 #19293
  • Bump spring-io/spring-gradle-build-action from 2.0.5 to 2.0.6 #19124
  • Bump spring-io/spring-release-actions from 0.0.4 to 0.0.5 #19183
  • Update micrometer-bom to 1.15.12 #19302
  • Update to Micrometer 1.15.11 #19224
  • Update to reactor-bom 2024.0.18 #19301

🔩 Build Updates

2026-04-21 03:52:41
spring-security

7.0.5

⭐ New Features

  • Add XML Based shouldWriteHeadersEagerly tests #19018
  • Merge Add CredentialRecordOwnerAuthorizationManager #19005

🪲 Bug Fixes

  • Add equals and hashcode to HttpMethodRequestMatcher #18963
  • auth_time claim doesn't show the time of the original authentication #18282
  • auth_time validation fails when SSO session is renewed #18978
  • Fallback defaultTargetUrl if refererHeader is empty #18981
  • Fix HttpSessionRequestCache#getMatchingRequest query string parsing #18972
  • Merge Handle null value in OnCommittedResponseWrapper header methods #18990
  • OAuth2 client sessionManagement ineffective with DefaultOidcUser #19022

🔨 Dependency Upgrades

  • Bump @springio/antora-extensions from 1.14.10 to 1.14.11 in /docs #19054
  • Bump @springio/antora-extensions from 1.14.7 to 1.14.9 in /docs #18953
  • Bump @springio/antora-extensions from 1.14.9 to 1.14.10 in /docs #19029
  • Bump @springio/asciidoctor-extensions from 1.0.0-alpha.17 to 1.0.0-alpha.18 in /docs #18957
  • Bump actions/upload-artifact from 7.0.0 to 7.0.1 #19096
  • Bump com.webauthn4j:webauthn4j-core from 0.31.1.RELEASE to 0.31.2.RELEASE #19021
  • Bump com.webauthn4j:webauthn4j-core from 0.31.2.RELEASE to 0.31.3.RELEASE #19114
  • Bump io.projectreactor:reactor-bom from 2025.0.4 to 2025.0.5 #19080
  • Bump org.apache.maven:maven-resolver-provider from 3.9.14 to 3.9.15 #19111
  • Bump org.springframework.data:spring-data-bom from 2025.1.4 to 2025.1.5 #19113
  • Bump org.springframework.ldap:spring-ldap-core from 4.0.2 to 4.0.3 #19098
  • Bump org.springframework:spring-framework-bom from 7.0.6 to 7.0.7 #19112
  • Bump spring-io/spring-gradle-build-action from 2.0.5 to 2.0.6 #18996
  • Bump spring-io/spring-release-actions from 0.0.3 to 0.0.4 #19095
  • Bump spring-io/spring-security-release-tools/.github/workflows/update-scheduled-release-version.yml from 1.0.14 to 1.0.15 #18948

❤️ Contributors

Thank you to all the contributors who worked on this release:

@rwinch

2026-04-21 02:45:58
spring-security

7.1.0-RC1

⭐ New Features

  • Add AllRequiredFactorsAuthorizationManager.anyOf #18960
  • Add PreFlightRequestFilter Support #18926
  • Add ConditionalAuthorizationManager #18919
  • Add MultiFactorCondition.WEBAUTHN_REGISTERED #18923
  • Add PreFlightRequestFilter Support #18980
  • Add PrincipalResolver to ExchangeFilterFunctions #18888
  • Add Support DPoP Customization #17202
  • Add XML Based shouldWriteHeadersEagerly tests #19019
  • AuthorizationManagerFactories.when #18920
  • Clarify @WithSecurityContext thread scope #18812
  • Construct SecureRandom in BCryptPasswordEncoder #18560
  • Enable Null checking in spring-security-oauth2-authorization-server via JSpecify #18937
  • Enable Null checking in spring-security-oauth2-client via JSpecify #17819
  • Enable Null checking in spring-security-oauth2-resource-server via JSpecify #17822
  • Exclude build output directories from nohttp source set #18928
  • Implement equals and hashCode in ImmutablePublicKeyCredentialUserEntity #18883
  • Improve And/Or-RequestMatcher/ServerWebExchangeMatcher API #18479
  • Merge Add CredentialRecordOwnerAuthorizationManager #19006
  • Move InetAddressMatcher to spring-security-core #18979
  • Polish oauth2-client tests with missing Content-Type header #19008
  • Prefer dispatcher context for authorize tag beans #18822
  • Publish authentication events in WebAuthn #18938
  • Relax client_id validation in AtJwtBuilder #18890
  • Remove compiler warnings for spring-security-access #18738
  • Remove compiler warnings in spring-security-web #18820
  • Remove Unnecessary ObjectProvider roleHierarchy parameter #18921
  • Revert snapshots to Spring Framework 7.0.+ #19024
  • Support Customizer<AdditionalRequiredFactorsBuilder>> #18922
  • Use idiomatic Kotlin in custom filter documentation #18976

🪲 Bug Fixes

  • Fix equals nullability annotations for jspecify compliance #18930
  • Merge Handle null value in OnCommittedResponseWrapper header methods #18991

🔨 Dependency Upgrades

  • Bump @springio/antora-extensions from 1.14.7 to 1.14.9 in /docs #18946
  • Bump @springio/antora-extensions from 1.14.9 to 1.14.10 in /docs #19030
  • Bump @springio/antora-extensions from 1.14.9 to 1.14.11 in /docs #19053
  • Bump @springio/asciidoctor-extensions from 1.0.0-alpha.17 to 1.0.0-alpha.18 in /docs #18913
  • Bump actions/upload-artifact from 7.0.0 to 7.0.1 #19091
  • Bump com.fasterxml.jackson:jackson-bom from 2.21.1 to 2.21.2 #18965
  • Bump com.nimbusds:oauth2-oidc-sdk from 11.34 to 11.35 #18977
  • Bump com.nimbusds:oauth2-oidc-sdk from 11.35 to 11.37 #19002
  • Bump com.webauthn4j:webauthn4j-core from 0.31.1.RELEASE to 0.31.2.RELEASE #19020
  • Bump com.webauthn4j:webauthn4j-core from 0.31.2.RELEASE to 0.31.3.RELEASE #19107
  • Bump gradle-wrapper from 9.4.0 to 9.4.1 #18959
  • Bump io.micrometer:micrometer-observation from 1.16.4 to 1.16.5 #19065
  • Bump io.projectreactor:reactor-bom from 2025.0.4 to 2025.0.5 #19079
  • Bump io.spring.nullability:io.spring.nullability.gradle.plugin from 0.0.12 to 0.0.13 #19067
  • Bump org-bouncycastle from 1.83 to 1.84 #19066
  • Bump org-jetbrains-kotlin from 2.3.10 to 2.3.20 #18915
  • Bump org.apache.httpcomponents.client5:httpclient5 from 5.6 to 5.6.1 #19106
  • Bump org.apache.maven:maven-resolver-provider from 3.9.14 to 3.9.15 #19105
  • Bump org.apereo.cas.client:cas-client-core from 4.0.4 to 4.1.0 #18974
  • Bump org.hibernate.orm:hibernate-core from 7.2.7.Final to 7.3.0.Final #18917
  • Bump org.hibernate.orm:hibernate-core from 7.3.0.Final to 7.3.1.Final #19063
  • Bump org.jetbrains.dokka from 2.1.0 to 2.2.0 #18998
  • Bump org.jetbrains.dokka:dokka-gradle-plugin from 2.1.0 to 2.2.0 #18999
  • Bump org.seleniumhq.selenium:htmlunit3-driver from 4.41.0 to 4.43.0 #19060
  • Bump org.seleniumhq.selenium:selenium-java from 4.41.0 to 4.42.0 #19056
  • Bump org.seleniumhq.selenium:selenium-java from 4.41.0 to 4.43.0 #19062
  • Bump org.springframework.data:spring-data-bom from 2025.1.4 to 2025.1.5 #19104
  • Bump org.springframework.ldap:spring-ldap-core from 4.0.2 to 4.0.3 #19097
  • Bump spring-io/spring-gradle-build-action from 2.0.5 to 2.0.6 #18993
  • Bump spring-io/spring-release-actions from 0.0.3 to 0.0.4 #19092
  • Bump spring-io/spring-security-release-tools from 1.0.14 to 1.0.15 #18942
  • Bump spring-io/spring-security-release-tools/.github/workflows/perform-release.yml from 1.0.14 to 1.0.15 #18944
  • Bump spring-io/spring-security-release-tools/.github/workflows/test.yml from 1.0.14 to 1.0.15 #18943
  • Bump spring-io/spring-security-release-tools/.github/workflows/update-scheduled-release-version.yml from 1.0.14 to 1.0.15 #18945
  • Bump tools.jackson:jackson-bom from 3.1.0 to 3.1.1 #19003
  • Bump tools.jackson:jackson-bom from 3.1.1 to 3.1.2 #19061

❤️ Contributors

Thank you to all the contributors who worked on this release:

@aspan, @dasog94, @evgeniycheban, @franticticktick, @gbaso, @jkuhel, @ribafish, @rwinch, @suuuuuuminnnnnn, @therepanic, @wonderfulrosemari, @yxinot, and @ziqin

2026-04-21 01:54:21
spring-security

6.5.10

⭐ New Features

  • Add CredentialRecordOwnerAuthorizationManager #19004
  • Add XML Based shouldWriteHeadersEagerly tests #19017
  • Clarify Session Management Persistence Documentation #18345
  • Update FilterChainProxy#getFilters(String) javadoc #18258

🪲 Bug Fixes

  • Add equals and hashcode to HttpMethodRequestMatcher #18914
  • auth_time validation fails when SSO session is renewed #18839
  • Fallback defaultTargetUrl if refererHeader is empty #18806
  • Fix HttpSessionRequestCache#getMatchingRequest query string parsing #16914
  • Fix documentation for Custom Authorization Manager #18362
  • Improve serialVersionUID check in tests #18474
  • Merge Handle null value in OnCommittedResponseWrapper header methods #18989
  • OAuth2 client sessionManagement ineffective with DefaultOidcUser #18622

🔨 Dependency Upgrades

  • Bump @springio/antora-extensions from 1.14.10 to 1.14.11 in /docs #19055
  • Bump @springio/antora-extensions from 1.14.7 to 1.14.9 in /docs #18956
  • Bump @springio/antora-extensions from 1.14.9 to 1.14.10 in /docs #19031
  • Bump @springio/asciidoctor-extensions from 1.0.0-alpha.17 to 1.0.0-alpha.18 in /docs #18952
  • Bump actions/upload-artifact from 7.0.0 to 7.0.1 #19094
  • Bump io.projectreactor:reactor-bom from 2024.0.16 to 2024.0.17 #19078
  • Bump io.spring.gradle:spring-security-release-plugin from 1.0.14 to 1.0.15 #18916
  • Bump org.apache.maven:maven-resolver-provider from 3.9.14 to 3.9.15 #19108
  • Bump org.hibernate.orm:hibernate-core from 6.6.44.Final to 6.6.45.Final #18966
  • Bump org.hibernate.orm:hibernate-core from 6.6.45.Final to 6.6.47.Final #19046
  • Bump org.hibernate.orm:hibernate-core from 6.6.47.Final to 6.6.48.Final #19064
  • Bump org.hibernate.orm:hibernate-core from 6.6.48.Final to 6.6.49.Final #19110
  • Bump org.springframework:spring-framework-bom from 6.2.17 to 6.2.18 #19109
  • Bump spring-io/spring-release-actions from 0.0.3 to 0.0.4 #19093
  • Bump spring-io/spring-security-release-tools from 1.0.14 to 1.0.15 #18954
  • Bump spring-io/spring-security-release-tools/.github/workflows/build.yml from 1.0.14 to 1.0.15 #18955
  • Bump spring-io/spring-security-release-tools/.github/workflows/deploy-artifacts.yml from 1.0.14 to 1.0.15 #18949
  • Bump spring-io/spring-security-release-tools/.github/workflows/deploy-schema.yml from 1.0.14 to 1.0.15 #18950
  • Bump spring-io/spring-security-release-tools/.github/workflows/perform-release.yml from 1.0.14 to 1.0.15 #18995
  • Bump spring-io/spring-security-release-tools/.github/workflows/test.yml from 1.0.14 to 1.0.15 #18951
  • Bump spring-io/spring-security-release-tools/.github/workflows/update-scheduled-release-version.yml from 1.0.14 to 1.0.15 #18994
  • Update to spring-security-release-tools 1.0.15 #18910

❤️ Contributors

Thank you to all the contributors who worked on this release:

@Kehrlann, @as1605, @johnycho, @ngocnhan-tran1996, @rwinch, and @sankranty

2026-03-17 02:16:34
spring-security

7.0.4

⭐ New Features

  • Update RestTemplateBuilder usage in opaque-token.adoc #18836

🪲 Bug Fixes

  • Fix GrantedAuthority.authority null in AuthoritiesAuthorizationManager #18784
  • Add Jackson Mixin for WebAuthnAuthentication #18878
  • Add Missing OnCommitedResponseWrapper Header Overrides #18799
  • Document the change in dependency coordinates with Spring Security 7 #18773
  • Ensure tests clear AuthorizationServerContextHolder #18768
  • Fix CookieRequestCache parameters #18864
  • Fix Flaky Crypto Tests #18842
  • Fix Jackson Deserializer for AuthenticationExtensionsClientOutputs #18897
  • HttpMessageConverterAuthenticationSuccessHandler Supports Jackson 3 #18834
  • OAuth2DeviceVerificationEndpointFilter should be applied after AuthorizationFilter #18873
  • Restore upgradeEncoding condition in DaoAuthenticationProvider #18788
  • saveAuthenticationRequest should read relayState from authenticationRequest #18884
  • SecurityExpressionRoot#hasAuthority should delegate to AuthorizationManagerFactory#hasAuthority #18487
  • ServerHttpSecurityConfiguration should not set userDetailsPasswordService to a null value #18276
  • TokenBasedRememberMeServices documentation snippets should compile #18642
  • Update request-matcher XML property to support PathPatternRequestMatcher #18737

🔨 Dependency Upgrades

  • Bump @antora/collector-extension from 1.0.2 to 1.0.3 in /docs #18853
  • Bump actions/upload-artifact from 6.0.0 to 7.0.0 #18810
  • Bump ch.qos.logback:logback-classic from 1.5.29 to 1.5.32 #18752
  • Bump com.webauthn4j:webauthn4j-core from 0.31.0.RELEASE to 0.31.1.RELEASE #18830
  • Bump io.projectreactor:reactor-bom from 2025.0.3 to 2025.0.4 #18877
  • Bump org-apache-maven-resolver from 1.9.25 to 1.9.26 #18751
  • Bump org-apache-maven-resolver from 1.9.26 to 1.9.27 #18792
  • Bump org.apache.maven:maven-resolver-provider from 3.9.12 to 3.9.13 #18861
  • Bump org.apache.maven:maven-resolver-provider from 3.9.13 to 3.9.14 #18887
  • Bump org.junit:junit-bom from 6.0.2 to 6.0.3 #18743
  • Bump org.springframework.data:spring-data-bom from 2025.1.3 to 2025.1.4 #18904
  • Bump org.springframework:spring-framework-bom from 7.0.4 to 7.0.5 #18764
  • Bump org.springframework:spring-framework-bom from 7.0.5 to 7.0.6 #18905
  • Update Antora UI Spring to v0.4.26 #18893
  • Update to spring-security-release-tools 1.0.15 #18909

❤️ Contributors

Thank you to all the contributors who worked on this release:

@busoco-sjb, @making, @meliezer, @ngocnhan-tran1996, @rwinch, @sephiroth-j, @therepanic, @thuri, and @ziqin