Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Bump spring-security-bom from 5.6.0 to 5.6.1 #6089

Conversation

dependabot[bot]
Copy link
Contributor

@dependabot dependabot bot commented on behalf of github Dec 20, 2021

Changelog: Update the Spring Security library from 5.6.0 to 5.6.1.

Bumps spring-security-bom from 5.6.0 to 5.6.1.

Release notes

Sourced from spring-security-bom's releases.

5.6.1

⭐ New Features

  • Document authentication helper method in WebClient integration #10468
  • Document authentication helper method in WebClient integration for Servlet Environments #10120
  • Document parameters converter in oauth2 client servlet docs #10469
  • Document parameters converter in oauth2 client servlet docs #10467

🪲 Bug Fixes

  • AuthorityAuthorizationManager incorrectly compares GrantedAuthority #10595
  • clockSkew Javadoc is not consistent with implementation #10535
  • Invalid_request failures in JwtTokenValidators are always turned into invalid_token errors #10560
  • Kotlin DSL examples in reactive oauth2 docs call build twice #10591
  • StaticServerHttpHeadersWriter should work with case-insensitive header names #10581

🔨 Dependency Upgrades

  • Update cas-client-core to 3.6.4 #10654
  • Update hibernate-entitymanager to 5.6.3.Final #10653
  • Update io.projectreactor to 2020.0.14 #10651
  • Update jackson-bom to 2.13.1 #10647
  • Update jackson-databind to 2.13.1 #10648
  • Update jackson-datatype-jsr310 to 2.13.1 #10649
  • Update junit-bom to 5.8.2 #10656
  • Update logback-classic to 1.2.9 #10646
  • Update mockk to 1.12.1 #10650
  • Update org.jetbrains.kotlin to 1.5.32 #10655
  • Update org.junit.jupiter to 5.8.2 #10657
  • Update org.springframework to 5.3.14 #10658
  • Update reactor-netty to 1.0.14 #10652
  • Update spring-ldap-core to 2.3.5.RELEASE #10659

❤️ Contributors

We'd like to thank all the contributors who worked on this release!

Commits
  • e38bf6e Release 5.6.1
  • 624e0da Update spring-ldap-core to 2.3.5.RELEASE
  • b28aa6c Update org.springframework to 5.3.14
  • 9e83b4b Update junit-bom to 5.8.2
  • e9854c9 Update org.jetbrains.kotlin to 1.5.32
  • 0345e29 Update cas-client-core to 3.6.4
  • 8bd5795 Update hibernate-entitymanager to 5.6.3.Final
  • 4fbc98d Update io.projectreactor to 2020.0.14
  • 44cdbd6 Update mockk to 1.12.1
  • a9af8c4 Update jackson-bom to 2.13.1
  • Additional commits viewable in compare view

Dependabot compatibility score

Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting @dependabot rebase.


Dependabot commands and options

You can trigger Dependabot actions by commenting on this PR:

  • @dependabot rebase will rebase this PR
  • @dependabot recreate will recreate this PR, overwriting any edits that have been made to it
  • @dependabot merge will merge this PR after your CI passes on it
  • @dependabot squash and merge will squash and merge this PR after your CI passes on it
  • @dependabot cancel merge will cancel a previously requested merge and block automerging
  • @dependabot reopen will reopen this PR if it is closed
  • @dependabot close will close this PR and stop Dependabot recreating it. You can achieve the same result by closing it manually
  • @dependabot ignore this major version will close this PR and stop Dependabot creating any more for this major version (unless you reopen the PR or upgrade to it yourself)
  • @dependabot ignore this minor version will close this PR and stop Dependabot creating any more for this minor version (unless you reopen the PR or upgrade to it yourself)
  • @dependabot ignore this dependency will close this PR and stop Dependabot creating any more for this dependency (unless you reopen the PR or upgrade to it yourself)

@dependabot dependabot bot added dependencies Pull requests that update a dependency file java Pull requests that update Java code labels Dec 20, 2021
Copy link
Member

@basil basil left a comment

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

This PR is now ready for merge. We will merge it after approximately 24 hours if there is no negative feedback. Please see the merge process documentation for more information about the merge process. Thanks!

@basil basil added the ready-for-merge The PR is ready to go, and it will be merged soon if there is no negative feedback label Dec 21, 2021
@basil
Copy link
Member

basil commented Dec 21, 2021

@dependabot rebase

Bumps [spring-security-bom](https://github.com/spring-projects/spring-security) from 5.6.0 to 5.6.1.
- [Release notes](https://github.com/spring-projects/spring-security/releases)
- [Changelog](https://github.com/spring-projects/spring-security/blob/main/RELEASE.adoc)
- [Commits](spring-projects/spring-security@5.6.0...5.6.1)

---
updated-dependencies:
- dependency-name: org.springframework.security:spring-security-bom
  dependency-type: direct:production
  update-type: version-update:semver-patch
...

Signed-off-by: dependabot[bot] <support@github.com>
@dependabot dependabot bot force-pushed the dependabot/maven/org.springframework.security-spring-security-bom-5.6.1 branch from e1f3b36 to 41148f2 Compare December 21, 2021 14:50
@basil basil merged commit 4eb5367 into master Dec 21, 2021
@dependabot dependabot bot deleted the dependabot/maven/org.springframework.security-spring-security-bom-5.6.1 branch December 21, 2021 18:51
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
dependencies Pull requests that update a dependency file java Pull requests that update Java code ready-for-merge The PR is ready to go, and it will be merged soon if there is no negative feedback
Projects
None yet
Development

Successfully merging this pull request may close these issues.

3 participants