Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Update dependency org.springframework:spring-core to v5.3.14 [SECURITY] #75

Open
wants to merge 1 commit into
base: master
Choose a base branch
from

Conversation

renovate[bot]
Copy link

@renovate renovate bot commented Mar 25, 2023

This PR contains the following updates:

Package Change Age Adoption Passing Confidence
org.springframework:spring-core 5.3.2 -> 5.3.14 age adoption passing confidence

GitHub Vulnerability Alerts

CVE-2021-22060

In Spring Framework versions 5.3.0 - 5.3.13, 5.2.0 - 5.2.18, and older unsupported versions, it is possible for a user to provide malicious input to cause the insertion of additional log entries. This is a follow-up to CVE-2021-22096 that protects against additional types of input and in more places of the Spring Framework codebase.

CVE-2021-22096

In Spring Framework versions 5.3.0 - 5.3.10, 5.2.0 - 5.2.17, and older unsupported versions, it is possible for a user to provide malicious input to cause the insertion of additional log entries.


Release Notes

spring-projects/spring-framework (org.springframework:spring-core)

v5.3.14

Compare Source

⭐ New Features
  • Add default methods to CachingConfigurer #​27811
  • Provide a variant of ListableBeanFactory.findAnnotationOnBean(String, Class) that does not initialize factory beans #​27796
  • Convert single null argument to Optional.empty() in SpEL varargs expression #​27795
  • Declare serialVersionUID on DefaultAopProxyFactory #​27784
  • The ReactorClientHttpConnector must apply mapper before tcpConfiguration() #​27749
  • Add getter for RequestMappingInfo builder config #​27723
  • Give warning when using capturing patterns with the AntPathMatcher #​27688
  • Support for customization of 404 response when RouterFunctionWebHandler finds no routes #​25358
  • ModelAndView.status does not work with RedirectView #​25092
  • ThreadPoolExecutorFactoryBean add ability to prestart threads #​1246
  • Support empty attributes in TagWriter #​910
🐞 Bug Fixes
  • AsyncConfigurer implementations are loaded too early #​27808
  • Possible NPE in Spring MVC LogFormatUtils #​27782
  • Extending CachingConfigurerSupport results in at least one log message about not being eligible for full post-processing #​27751
  • WebFlux ServerResponse does not overwrite already present response headers #​27741
  • Passing single null value in varargs SpEL expression results in NullPointerException #​27719
  • UriUtils::extractFileExtension does not properly handle empty file names #​27639
  • References of CountingBeforeAdvice target its previous location #​22246
  • ProxyFactoryBean getObject called before setInterceptorNames, silently creating an invalid proxy [SPR-7582] #​12238
📔 Documentation
  • Remove references to AsyncConfigurerSupport as AsyncConfigurer should be used instead #​27812
  • Fix javadoc reference to ThrowsAdvice #​27804
  • Suggested WebSocket config causes circular bean reference #​27746
  • Document the difference in generics resolution between @Autowired and beanFactory.getBeanProvider #​27727
  • Clarify that interface-level cache annotations work for target-class proxies as well #​27726
  • SchedulerFactoryBean no longer sets the job store's DataSource when the job store class has been customized #​27709
  • Fix typo #​27699
  • Fix incorrect example of error handling in WebClient Javadoc #​27645
  • Missing reference documentation for WebSocketScope #​25172
  • Clarify behaviour of AnnotationBeanNameGenerator with acronyms #​2030
  • Fix simple data format in appendix #​1025
  • Update StoredProcedure.java declareParameter method JavaDoc #​1000
  • Document @Bean definitions via default methods #​767
  • Improved DataBinder Javadoc for xxx*yyy pattern matching. #​699
🔨 Dependency Upgrades
❤️ Contributors

We'd like to thank all the contributors who worked on this release!

v5.3.13

Compare Source

⭐ New Features
  • Use ByteArrayDecoder in DefaultClientResponse::createException #​27666
  • Improve the efficiency of UrlPathHelper.getSanitizedPath() #​27623
  • Add option to cleanup multipart temp files #​27613
  • Add support for custom expression parsing in CachedExpressionEvaluator #​27604
  • Use LocalDataSourceJobStore only if one is not specified via Quartz properties #​27560
  • Introduce TypeFilterUtils for processing @ComponentScan.Filter #​27553
  • Improve mapping function in ExtendedEntityManagerCreator.createProxy() #​27456
🐞 Bug Fixes
  • Static resources are missing when jar does not have a directory entry #​27624
  • MultipartParser emits DataBufferLimitException about "Part headers exceeded the memory usage limit" unexpectedly #​27612
  • UndertowHeadersAdapter's remove() method violates Map contract #​27592
  • SpEL vararg method invocation fails if string literal contains a comma #​27582
📔 Documentation
  • Fix grammar in webflux-webclient.adoc #​27657
  • Lazy annotation throws exception if non-required bean does not exist #​27649
  • Clarify LogFormatUtils limitLength vs replaceNewlines parameters #​27632
  • PersistenceExceptionTranslationInterceptor attempting to instantiate prototype PersistenceExceptionTranslator beans #​26412
🔨 Dependency Upgrades
❤️ Contributors

We'd like to thank all the contributors who worked on this release!

v5.3.12

Compare Source

🐞 Bug Fixes
  • Update warn log message for empty static resource locations #​27575
  • Default content type of response changed in v5.3.11 #​27573
  • Fix assertion failure messages in DefaultDataBuffer.checkIndex() #​27567
📔 Documentation
  • Incorrect Javadoc in [NamedParameter]JdbcOperations.queryForObject methods regarding exceptions #​27559
❤️ Contributors

We'd like to thank all the contributors who worked on this release!

v5.3.11

Compare Source

⭐ New Features
  • Enhance DefaultResponseErrorHandler to allow logging complete error response body #​27552
  • Include correct keyword in CookieAssertions failure messages #​27550
  • Use Arrays.hashCode() in ByteArrayResource.hashCode() #​27544
  • Allow default CacheAwareContextLoaderDelegate configuration via a system property #​27540
  • Invoke bean-derived (Auto)Closeable.close() method directly #​27504
  • Defensive reference to JNDI API for JDK 9+ (optional java.naming module) #​27483
  • DefaultMessageListenerContainer does not log an error/warning when consumer tasks have been rejected #​27451
  • Provide accessor on externallyManaged RootBeanDefinition attributes #​27449
  • Allow to avoid class validation in CglibAopProxy via ProxyFactory #​27439
  • Add support for non-public record declarations #​27437
  • Emit WebClientResponseException for malformed HTTP response #​27262
  • DatabasePopulatorUtils.execute should commit if the current Connection has auto-commit set to false #​27008
🐞 Bug Fixes
  • CronTrigger uses new Date() instead of context's Clock #​27546
  • Performance impact of con.getContentLengthLong() in AbstractFileResolvingResource.isReadable() downloading huge jars to check component length #​27541
  • Performance impact of ResourceUrlEncodingFilter on HttpServletResponse#encodeURL #​27538
  • UriTemplateRequestEntity doesn't override hashCode() and equals() #​27531
  • DataBufferUtils.write loses context #​27517
  • Avoid duplicate JCacheOperationSource bean registration in <cache:annotation-driven /> #​27499
  • Proxy generation with Java 17 fails with "Cannot invoke "Object.getClass()" because "cause" is null" #​27490
  • MediaType.sortBySpecificityAndQuality throws java.lang.IllegalArgumentException: Comparison method violates its general contract #​27488
  • Leading whitespaces are removed while reading SSE response #​27473
  • Non-escaped closing curly brace in RegEx results in initialization error on Android #​27467
  • ConcurrentReferenceHashMap's entrySet violates the Map contract #​27454
  • Avoid early ConversionService determination in StandardBeanExpressionResolver #​27446
  • Spring Framework >= 5.3.8 ASM ClassReader fails to parse class file due to InputStream optimization #​27429
  • StringUtils.collectionToDelimitedString(?) fails with NullPointerException when the collection contains null #​27419
  • Spring HATEOAS results in 406 with Kotlin Coroutine and ResponseEntity in WebFlux #​27292
📔 Documentation
  • Remove remark about missing caching API. #​27501
🔨 Dependency Upgrades
❤️ Contributors

We'd like to thank all the contributors who worked on this release!

v5.3.10

Compare Source

⭐ New Features
  • Invalid JavaBean property 'logoutHandlers' being accessed (warning in the logs for Spring Security's ConcurrentSessionFilter) #​27372
  • Convenient configuration of type permissions for XStream 1.4.18 #​27343
  • Add SmallRye Mutiny support to ReactiveAdapterRegistry #​27331
  • Introduce ExceptionCollector testing utility #​27316
  • Support TimeUnit in the @Scheduled annotation #​27309
  • Make it possible to determine if circular references are prohibited or if the cycle just couldn't be broken #​27289
  • Support Charset for character encoding in MockMvc #​27231
  • Support default character encoding for response in MockMvc #​27230
  • Introduce setDefaultCharacterEncoding() in MockHttpServletResponse #​27214
  • Use MessageSource for @ExceptionHandler methods #​27203
  • ResponseStatusException.initCause always throws IllegalStateException #​27196
  • Introduce soft assertions for WebTestClient #​26969
  • Introduce soft assertions for MockMvc #​26917
  • Blockhound flags a blocking call when WebFlux serves a static resource #​26631
  • Optimize memory allocations in StringUtils#cleanPath #​26316
  • InvocableHandlerMethod calls makeAccessible(getBridgedMethod()) on every call [SPR-15230] #​19795
🐞 Bug Fixes
  • Support char, float, and double primitive default values in BeanUtils.instantiateClass() #​27390
  • Fix memory leak on AOP Proxy class definition cache #​27375
  • Fix response body missing 1st byte inside UnknownContentTypeException #​27374
  • CommonsMultipartResolver and DEBUG logging lead to empty fileMap in MultipartHttpServletRequest #​27350
  • Fix UrlPathHelper#shouldRemoveSemicolonContent() #​27303
  • CompositeUriComponentsContributor#hasContributors: method name is not compliant with its intention #​27271
  • Error with formatMapping method in AbstractMethodMessageHandler.java #​27247
  • Apply default ResultHandlers before default ResultMatchers in MockMvc #​27225
  • MockHttpServletResponse.characterEncoding should not be @Nullable #​27219
  • WebSocketMessageBrokerStats.getExecutorStatsInfo() throws exception if Executor is not a ThreadPoolExecutor #​27209
  • HtmlUnitRequestBuilder ignores file uploaded via HtmlFileInput.setData() #​27199
📔 Documentation
  • Fix wording in Javadoc of ClientResponse.mutate() #​27389
  • Fix some typos and mistakes in docs #​27388
  • Fix misplaced comma in AOP doc #​27387
  • Fix Kotlin example for filtering handler functions #​27337
  • Document when prepareTestInstance() is invoked when using the SpringMethodRule #​27305
  • Fix duplicated "the" occurrences in Javadoc and XSD #​27291
  • Fix typo in DefaultPartHttpMessageReader #​27260
  • Fix reference to Optional.isPresent() in ObjectUtils.isEmpty() #​27223
  • Clarify that ClientRequest.from(..) also copies body #​27220
  • @Cacheable caches empty Optionals but documentation states otherwise #​27184
  • Reference docs missing left-hand side navigation #​27177
🔨 Dependency Upgrades
❤️ Contributors

We'd like to thank all the contributors who worked on this release!

v5.3.9

Compare Source

⭐ New Features
  • Configure CommonsMultipartResolver to support specific HTTP methods #​27161
  • Allow BeanDefinitionBuilder to set an instance supplier with a ResolvableType #​27160
  • Reason of @ResponseStatus on handler method is not resolved by MessageSource #​27156
  • ResourceHandlerRegistry#getHandlerMapping should initialize handler once in outer loop #​27153
  • Set synthetic flag using BeanDefinitionBuilder #​27141
  • BeanCreationException error message should always include declaring class of constructor (or factory method) #​27139
  • Improve Jetty 10 check in JettyClientHttpResponse #​27136
  • Jetty10RequestUpgradeStrategy use an old jetty 9 class HandshakeRFC6455 #​27121
  • ClassNotFoundException using Jetty 10 and its reactive client #​27112
  • Use StringBuilder.append(char) where possible #​27098
  • Consider "wss" and "https" for secure flag in Forwarded header checks #​27097
  • SynchronossPartHttpMessageReader should only create temp directory when needed #​27092
  • Implement equals, hashCode, & toString in BeanMethod and *Metadata types #​27076
  • Remove logging dependency in BeanUtils #​27070
  • Exclude sealed interfaces from auto-proxying (for JDK 17 compatibility) #​27027
  • Blockhound error when running with transaction with a TransactionOperator #​26955
  • Configure StandardServletMultipartResolver to only support multipart/form-data #​26826
  • Add a way to set executeExistingDelayedTasksAfterShutdown from ThreadPoolTaskScheduler #​26719
  • Apply dynamic changes in ThreadPoolTaskExecutor before setting local value #​26700
🪲 Bug Fixes
  • JettyHttpHandlerAdapter is not aware of Server[Request|Response]Wrapper #​27146
  • {*path} pattern (CaptureTheRestPathElement) includes undocumented leading slash in @PathVariable path #​27132
  • NoSuchMethodError when invoke JettyWebSocketSession.getRemoteAddress in jetty 10 #​27120
  • CronExpression is still broken on spring-context-5.3.8 #​27117
  • SimpleMethodMetadataReadingVisitor.Source.toString() omits separator for method arguments #​27095
  • DefaultPathSegment allows shared empty parameters map to be mutated #​27064
  • AOP auto-proxying with proxyTargetClass=true and introduction advice does not work for JDK proxy targets #​27044
  • ServletRequestDataBinder assumes Standard servlet multipart handling #​26999
  • DataClassRowMapper should not override Kotlin init properties #​26569
📔 Documentation
  • Add Javadoc @since to BeanDefinitionBuilder.setSynthetic() #​27155
  • Fix link to Javadoc API #​27151
  • Added description for HandlerInterceptor #​27122
  • Fix typo in core-beans.adoc #​27113
  • Fix typo in BeanDefinitionDsl.kt #​27105
  • Improve docs for getContentAsByteArray method of ContentCachingRequestWrapper #​27068
  • Fix explanation on default settings for content negotiation in reference doc #​27067
  • Document that any @Valid* annotation triggers validation in the reference manual #​27050
  • Improve RequestPartMethodArgumentResolver Javadoc #​27043
  • Improve RequestResponseBodyMethodProcessor Javadoc #​27042
  • Clarify that baseName in ResourceBundleMessageSource does not support multiple locations #​27038
  • Link alternate documentation formats #​27015
🔨 Dependency Upgrades
❤️ Contributors

We'd like to thank all the contributors who worked on this release!

v5.3.8

Compare Source

⭐ New Features
  • HttpComponentsClientHttpConnector should close underlying resources #​27032
  • Default value of StandaloneMockMvcBuilder.useSuffixPatternMatch differs from the same property in RequestMappingHandlerMapping #​27030
  • Lookup method autowiring ignores method's generic info #​26998
  • Set BEST_MATCHING_PATTERN_ATTRIBUTE on requests with WebMvc.fn #​26963
  • Remove jackson-module-kotlin warning #​26962
  • Switch back to parallel thread after WebSession id is generated #​26958
  • Introduce ResponseEntity.internalServerError() #​26952
  • Polish PORT_PATTERN in UriComponentsBuilder #​26951
  • Deprecate/Remove internal APIs in ScriptUtils implementations #​26947
  • Consider returning static DefaultApplicationStartup step #​26939
  • Exception in Tomcat when SockJS top URL is a WebSocket upgrade #​26933
  • Improve support for port numbers in allowedOriginPattern of CorsConfiguration #​26927
  • Add ApplicationEvent constructor for specifying timestamp #​26871
  • Add awaitExchangeOrNull extension function to reactive webclient #​26778
🪲 Bug Fixes
  • Revisit fix for gh-26905 in UriComponentsBuilder #​27039
  • MultipartHttpMessageWriter in WebClient doesn't use custom Jackson Encoder since 5.3.3 #​27017
  • PartFile name lost when building a MultiPart #​27007
  • No replacement of deprecated CronSequenceGenerator.isValidExpression #​26996
  • NPE if StompEndpointRegistry has allowedOrigins with null #​26987
  • CronExpression is broken on spring-context-5.3.6 #​26964
  • FlightRecorderApplicationStartup is not thread safe #​26941
  • Ignore delimiter enclosed in double quotes in ScriptUtils #​26935
  • Ignore comments when searching for SQL statement delimiter in ScriptUtils #​26911
📔 Documentation
  • spring-framework-main-code attribute has not been expanded in docs #​27041
  • Document that class-level @ResponseStatus is inherited by @ExceptionHandler methods #​27031
  • Improve @Transactional docs regarding method visibility #​27003
  • Fix @Transactional examples regarding method visibility #​27001
  • Fix typo in code example #​26980
  • Document transactional semantics for @TransactionalEventListener after completion methods #​26974
  • Fix typo #​26973
  • Fix broken Javadoc tags #​26967
🔨 Dependency Upgrades
❤️ Contributors

We'd like to thank all the contributors who worked on this release!

v5.3.7

Compare Source

⭐ New Features
  • Ensure multipart temp directories do not collide #​26931
  • SpringBeanAutowiringSupport should log at warn level when autowiring fails #​26925
  • spring-context-indexer doesn't support Java records #​26909
  • Ignore trailing slash in CorsConfiguration origin patterns #​26892
  • RSocketRequester disposal of underlying RSocketClient #​26886
  • Add PreFlightRequestWebFilter #​26885
  • Avoid memory leak when PropertyComparator is reused #​26869
  • Support MySQL safe updates mode in MySQLMaxValueIncrementer #​26858
  • HttpStatus.resolve allocates HttpStatus.values() once per invocation #​26842
  • InvalidPathException in log when running SpringBootTest with NIO Path property on Windows #​26828
  • Use String.startsWith() instead of String.substring() in PatternMatchUtils #​26822
  • Access to the cachedSessions in CachingConnectionFactory #​26811
  • Reduce log level in ExecutorConfigurationSupport.initialize #​26810
  • Avoid exceptions when evaluating validation hints #​26787
🪲 Bug Fixes
  • UriComponentsBuilder handles invalid port numbers correctly #​26905
  • Incorrect check in AbstractBrokerRegistration's constructor #​26896
  • DataClassRowMapper doesn't correctly convert generic fields #​26881
  • CorsRegistration#combine is a noop #​26877
  • LinkedCaseInsensitiveMap#putIfAbsent does not honor the case where the key is associated with a null value #​26868
  • Provide control over fallback charset to use in WebClientResponseException #​26866
  • @ModelAttribute(binding=false) is not honored with WebFlux #​26856
  • Fix Kotlin filter parameter bug in Router DSLs #​26838
  • AbstractListenerReadPublisher publishing onComplete signal before onNext during heavy load #​26834
  • MockMvc's MVC_RESULT_ATTRIBUTE lost with HandlerMappingIntrospector and RouterFunctions in use #​26833
  • webmvc.fn onError doesn't work with CompletableFuture #​26831
  • Daylight saving time issue in CronExpression #​26830
  • HandlerMappingIntrospector does not work with PathPattern backed HandlerMappings #​26814
  • Addition of fallback patterns to DateFormatter loses cause in Spring 5.3.5 #​26804
  • Support empty file uploads with HtmlUnit and MockMvc #​26799
  • Cache setup failure does not provide nested cause #​25250
  • Fix web parameters resolution when injected via constructor #​25200
📔 Documentation
  • Document feature to load @ModelAttribute through type conversion from a request value #​26873
  • Improve advice on response handling in an ExchangeFilterFunction #​26819
  • Remove leftover Javadoc from WebClient #​26807
  • Add information about changed behaviour for resolving @AuthenticationPrincipal annotation #​26791
  • Update Javadoc on CORS in spring-websocket #​26753
  • Add advice on Spring MVC path matching for 5.3 and above to the reference documentation #​26750
🔨 Dependency Upgrades
❤️ Contributors

We'd like to thank all the contributors who worked on this release!

v5.3.6

Compare Source

⭐ New Features
  • Make sure file storage directory exists before usage in DefaultPartHttpMessageReader #​26790
  • Allow spring-expression to be more easily repackaged for embedding in third-party JARs #​26779
  • Support 'Accept-Patch' header in MVC and WebFlux #​26759
  • Invalid IPv6 Address with X-Forwarded-For leads to number format exception #​26748
  • awaitBodyOrNull function to handle empty body #​26731
  • Reactive AbstractErrorWebExceptionHandler#htmlEscape() may be blocking #​26712
  • Improve Docs on Testing Streaming Responses in Spring MVC #​26687
  • Exceptions for missing request values should expose information when they are missing after conversion #​26679
🪲 Bug Fixes
  • Addition of fallback patterns to temporal parser loses cause in Spring 5.3.5 #​26777
  • ResourceHttpRequestHandler fails to resolve encoded paths when PathPattern is used #​26775
  • Scheduling a task that runs once a day results in March 28 being skipped #​26744
  • Support UTF-8 in DefaultPartHttpMessageReader #​26736
  • Root path resolution for java.nio.Path properties does not work on Linux anymore #​26702
  • @DirtiesContext not applied when class-level @EnabledIf evaluates to false #​26694
  • MappedInterceptor in 5.3 does not support all AntPatternMatcher patterns #​26690
  • BridgeMethodResolver#isBridgeMethodFor return incorrect result for kotlin code in certain circumstance #​26585
📔 Documentation
  • Update ref docs regarding RequiredAnnotationBeanPostProcessor registration #​26783
  • Update documentation for <context:annotation-config/> #​26782
  • Fix javadoc link syntax #​26776
🔨 Dependency Upgrades
❤️ Contributors

We'd like to thank all the contributors who worked on this release!

v5.3.5

Compare Source

⭐ New Features
  • Expose @JmsListener endpoint id to annotation-derived listener container (for transaction definition name) #​26683
  • Add support for Oracle bind marker scheme using R2DBC #​26680
  • Add HTTP request cookies to the WebSocket handshake info #​26674
  • Add an MockMVC alwaysDo equivalent to WebTestClient #​26662
  • Ensure ClientResponse logPrefix Contains the Connection Id When Available #​26656
  • Make use of Reactor Netty API for request id #​26649
  • WriteResultPublisher does not pass cancel signals #​26642
  • @EventListener annotated bean cannot be removed from the ApplicationEventMulticaster #​26638
  • Support global @MessageExceptionHandler via @ControllerAdvice in RSocket #​26636
  • Support UTF-16 and UTF-32 in Jackson HttpMessageConverters #​26627
  • Add missing nullable annotation to ResponseEntity ok convenience method #​26613
  • OncePerRequestFilter.isAsyncDispatch may return a NPE #​26602
  • Allow AOP proxies to be created using the original ClassLoader #​26601
  • WebSocketHandlerRegistration is missing option for allowedOriginPatterns #​26593
  • HandlerMapping for WebSocket Requests Only #​26565
  • Support cookies with Expires attribute but no Max-Age attribute in MockHttpServletResponse #​26558
  • Allow logging REST endpoint mappings independent of other log categories #​26539
  • Introduce 'idleReceivesPerTaskLimit' in DefaultMessageListenerContainer #​26442
  • Improve handling of malformed Accept header for @ExceptionHandler methods #​24539
  • Support fallback parsing patterns in @DateTimeFormat #​20292

Configuration

📅 Schedule: Branch creation - "" (UTC), Automerge - At any time (no schedule defined).

🚦 Automerge: Enabled.

Rebasing: Whenever PR is behind base branch, or you tick the rebase/retry checkbox.

🔕 Ignore: Close this PR and you won't be reminded about this update again.


  • If you want to rebase/retry this PR, check this box

This PR was generated by Mend Renovate. View the repository job log.

@renovate
Copy link
Author

renovate bot commented Mar 25, 2023

Branch automerge failure

This PR was configured for branch automerge. However, this is not possible, so it has been raised as a PR instead.


  • Branch has one or more failed status checks

@renovate renovate bot force-pushed the renovate/maven-org.springframework-spring-core-vulnerability branch from 1c016ae to 6069b7c Compare April 17, 2023 17:41
@renovate renovate bot changed the title Update dependency org.springframework:spring-core to v5.3.26 [SECURITY] Update dependency org.springframework:spring-core to v5.3.27 [SECURITY] Apr 17, 2023
@renovate renovate bot force-pushed the renovate/maven-org.springframework-spring-core-vulnerability branch from 6069b7c to 589a0bf Compare January 23, 2024 19:33
@renovate renovate bot changed the title Update dependency org.springframework:spring-core to v5.3.27 [SECURITY] Update dependency org.springframework:spring-core to v6 [SECURITY] Jan 23, 2024
@renovate renovate bot force-pushed the renovate/maven-org.springframework-spring-core-vulnerability branch from 589a0bf to f7113c0 Compare January 24, 2024 19:48
@renovate renovate bot changed the title Update dependency org.springframework:spring-core to v6 [SECURITY] Update dependency org.springframework:spring-core to v5.3.27 [SECURITY] Jan 24, 2024
@renovate renovate bot force-pushed the renovate/maven-org.springframework-spring-core-vulnerability branch from f7113c0 to 82b17fe Compare February 2, 2024 22:24
@renovate renovate bot changed the title Update dependency org.springframework:spring-core to v5.3.27 [SECURITY] Update dependency org.springframework:spring-core to v5.3.14 [SECURITY] Feb 2, 2024
@renovate renovate bot changed the title Update dependency org.springframework:spring-core to v5.3.14 [SECURITY] Update dependency org.springframework:spring-core to v5.3.14 [SECURITY] - autoclosed Feb 24, 2024
@renovate renovate bot closed this Feb 24, 2024
@renovate renovate bot deleted the renovate/maven-org.springframework-spring-core-vulnerability branch February 24, 2024 07:41
@renovate renovate bot changed the title Update dependency org.springframework:spring-core to v5.3.14 [SECURITY] - autoclosed Update dependency org.springframework:spring-core to v5.3.14 [SECURITY] Feb 24, 2024
@renovate renovate bot restored the renovate/maven-org.springframework-spring-core-vulnerability branch February 24, 2024 10:43
@renovate renovate bot reopened this Feb 24, 2024
@renovate renovate bot force-pushed the renovate/maven-org.springframework-spring-core-vulnerability branch from 82b17fe to 27ee661 Compare February 24, 2024 10:43
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

Successfully merging this pull request may close these issues.

0 participants