Security
- CVE-2026-59284 — Spring Cloud Commons no allow list for writable env actuator endpoint
What's Changed
- Bouncycastle has been upgraded to 1.85.2 and Spring Cloud Commons now uses the Bouncycastle BOM in 34d9ec2
- GH-1644: Document RefreshScopeHealthIndicator and how to disable it by @won-seoop in #1697
- Do not recursively try to reset configuration properties for library types by @ryanjbaxter in #1699
- Skip resetting beans to default vaules if there is no default constructor by @ryanjbaxter in #1701
- Bump antora from 3.2.0-alpha.12 to 3.2.0-rc.2 in /docs by @dependabot[bot] in #1704
- Bump actions/checkout from 6 to 7 by @dependabot[bot] in #1702
- Re-enable lifecycle MVC endpoint tests by @hutiefang76 in #1707
- Polish note about @ConfigurationProperties can't be refreshed by @quaff in #1466
- Add null protection for property names in AbstractEnvironmentDecrypt by @ryanjbaxter in #1713
- Bump @springio/antora-extensions from 1.14.12 to 1.14.13 in /docs by @dependabot[bot] in #1718
- Autowire beans when rebinding by @ryanjbaxter in #1720
- Add a per-bean-name lock around destroy/reset/re-populate/re-initialize steps in rebind by @ryanjbaxter in #1721
- Escape asterisk character by @ngocnhan-tran1996 in #1722
New Contributors
- @won-seoop made their first contribution in #1697
- @hutiefang76 made their first contribution in #1707
Full Changelog: v5.0.2...v5.0.3