Skip to content

Update all patch/minor versions (4.0) - #4378

Open
renovate[bot] wants to merge 1 commit into
4.0from
renovate/4.0-all-patchminor-versions
Open

Update all patch/minor versions (4.0)#4378
renovate[bot] wants to merge 1 commit into
4.0from
renovate/4.0-all-patchminor-versions

Conversation

@renovate

@renovate renovate Bot commented Sep 1, 2026

Copy link
Copy Markdown
Contributor

This PR contains the following updates:

Package Type Update Change Age Confidence
tomcat (source) final patch 11.0.24-jre21-temurin-jammy11.0.25-jre21-temurin-jammy age confidence
underscore.js (source) patch 1.13.71.13.8 age confidence
org.springframework.security:spring-security-web (source) dependencies patch 7.1.07.1.1 age confidence
org.springframework.security:spring-security-config (source) dependencies patch 7.1.07.1.1 age confidence
org.springframework:spring-webmvc dependencies patch 7.0.87.0.9 age confidence
org.springframework:spring-web dependencies patch 7.0.87.0.9 age confidence
org.springframework:spring-tx dependencies patch 7.0.87.0.9 age confidence
org.springframework:spring-test dependencies patch 7.0.87.0.9 age confidence
org.springframework:spring-orm dependencies patch 7.0.87.0.9 age confidence
org.springframework:spring-jdbc dependencies patch 7.0.87.0.9 age confidence
org.springframework:spring-core dependencies patch 7.0.87.0.9 age confidence
org.springframework:spring-context dependencies patch 7.0.87.0.9 age confidence
org.springframework:spring-beans dependencies patch 7.0.87.0.9 age confidence
org.springframework:spring-aspects dependencies patch 7.0.87.0.9 age confidence
joda-time:joda-time (source) dependencies patch 2.14.22.14.3 age confidence
net.sf.jasperreports:jasperreports-pdf (source) dependencies patch 7.0.77.0.8 age confidence
net.sf.jasperreports:jasperreports-json (source) dependencies patch 7.0.77.0.8 age confidence
net.sf.jasperreports:jasperreports-jdt (source) dependencies patch 7.0.77.0.8 age confidence
net.sf.jasperreports:jasperreports-functions (source) dependencies patch 7.0.77.0.8 age confidence
net.sf.jasperreports:jasperreports-fonts (source) dependencies patch 7.0.77.0.8 age confidence
net.sf.jasperreports:jasperreports-excel-poi (source) dependencies patch 7.0.77.0.8 age confidence
net.sf.jasperreports:jasperreports (source) dependencies patch 7.0.77.0.8 age confidence
io.hypersistence:hypersistence-utils-hibernate-63 dependencies patch 3.15.43.15.5 age confidence
org.apache.httpcomponents.client5:httpclient5 (source) dependencies patch 5.6.35.6.4 age confidence
org.hibernate:hibernate-core (source) dependencies patch 6.6.54.Final6.6.56.Final age confidence

Release Notes

jashkenas/underscore (underscore.js)

v1.13.8

Compare Source

spring-projects/spring-security (org.springframework.security:spring-security-web)

v7.1.1

Compare Source

⭐ New Features
  • Fix Broken DefaultLoginPageGeneratingFilter Javadoc Link #​19252
  • Remove BeanResolver Null Checks #​19209
  • Remove Unnecessary AuthorizationDecision Cast #​19283
  • Update One-Time Token Docs for Renamed APIs #​19274
🪲 Bug Fixes
  • Correct validation logic in CasAuthenticationToken #​19372
  • Differentiate Forwarded and X-Forwarded headers in proxy docs #​19477
  • Find mixed-case names in InMemoryUserDetailsManager#changePassword #​19539
  • Fix OAuth2PushedAuthorizationRequestUri parsing #​19445
  • Update JavaDoc Links in Reference #​19199
  • Validate Parameter in setPostAuthenticationChecks #​19277
🔨 Dependency Upgrades
  • Bump @springio/antora-extensions from 1.14.12 to 1.14.13 in /docs #​19503
  • Bump actions/checkout from 6.0.3 to 7.0.0 #​19351
  • Bump actions/checkout from 7.0.0 to 7.0.1 #​19464
  • Bump actions/setup-java from 5.2.0 to 5.3.0 #​19352
  • Bump actions/setup-java from 5.3.0 to 5.4.0 #​19380
  • Bump actions/setup-java from 5.4.0 to 5.5.0 #​19430
  • Bump actions/setup-java from 5.5.0 to 5.6.0 #​19453
  • Bump actions/setup-java from 5.6.0 to 5.7.0 #​19501
  • Bump antora from 3.2.0-alpha.12 to 3.2.0-rc.2 in /docs #​19385
  • Bump ch.qos.logback:logback-classic from 1.5.34 to 1.5.35 #​19374
  • Bump ch.qos.logback:logback-classic from 1.5.35 to 1.5.36 #​19389
  • Bump ch.qos.logback:logback-classic from 1.5.36 to 1.5.37 #​19396
  • Bump ch.qos.logback:logback-classic from 1.5.37 to 1.5.38 #​19431
  • Bump ch.qos.logback:logback-classic from 1.5.38 to 1.6.0 #​19467
  • Bump ch.qos.logback:logback-classic from 1.6.0 to 1.6.1 #​19476
  • Bump ch.qos.logback:logback-classic from 1.6.1 to 1.6.2 #​19556
  • Bump ch.qos.logback:logback-classic from 1.6.2 to 1.6.3 #​19564
  • Bump com.fasterxml.jackson:jackson-bom from 2.22.0 to 2.22.1 #​19419
  • Bump com.fasterxml.jackson:jackson-bom from 2.22.1 to 2.22.2 #​19566
  • Bump com.nimbusds:oauth2-oidc-sdk from 11.37.2 to 11.38.1 #​19439
  • Bump com.nimbusds:oauth2-oidc-sdk from 11.38.1 to 11.38.2 #​19525
  • Bump com.unboundid:unboundid-ldapsdk from 7.0.4 to 7.0.5 #​19322
  • Bump com.webauthn4j:webauthn4j-core from 0.31.6.RELEASE to 0.31.7.RELEASE #​19313
  • Bump com.webauthn4j:webauthn4j-core from 0.31.7.RELEASE to 0.31.8.RELEASE #​19409
  • Bump com.webauthn4j:webauthn4j-core from 0.31.8.RELEASE to 0.31.9.RELEASE #​19496
  • Bump gradle-wrapper from 9.5.1 to 9.6.0 #​19360
  • Bump gradle-wrapper from 9.6.0 to 9.6.1 #​19393
  • Bump gradle-wrapper from 9.6.1 to 9.7.0 #​19516
  • Bump io.spring.nullability:io.spring.nullability.gradle.plugin from 0.0.13 to 0.0.14 #​19378
  • Bump org-bouncycastle from 1.84 to 1.85 #​19437
  • Bump org-jetbrains-kotlin from 2.4.0 to 2.4.10 #​19447
  • Bump org-opensaml5 from 5.2.2 to 5.2.3 #​19358
  • Bump org.apache.httpcomponents.client5:httpclient5 from 5.6.1 to 5.6.2 #​19401
  • Bump org.apache.httpcomponents.client5:httpclient5 from 5.6.2 to 5.6.3 #​19495
  • Bump org.apache.httpcomponents.client5:httpclient5 from 5.6.3 to 5.6.4 #​19538
  • Bump org.apache.kerby:kerb-simplekdc from 2.1.1 to 2.1.2 #​19387
  • Bump org.hibernate.orm:hibernate-core from 7.4.0.Final to 7.4.1.Final #​19312
  • Bump org.hibernate.orm:hibernate-core from 7.4.1.Final to 7.4.2.Final #​19364
  • Bump org.hibernate.orm:hibernate-core from 7.4.2.Final to 7.4.3.Final #​19402
  • Bump org.hibernate.orm:hibernate-core from 7.4.3.Final to 7.4.4.Final #​19416
  • Bump org.hibernate.orm:hibernate-core from 7.4.4.Final to 7.4.5.Final #​19443
  • Bump org.junit:junit-bom from 6.1.0 to 6.1.1 #​19395
  • Bump org.junit:junit-bom from 6.1.1 to 6.1.2 #​19442
  • Bump org.junit:junit-bom from 6.1.2 to 6.1.3 #​19524
  • Bump org.junit:junit-bom from 6.1.2 to 6.1.3 #​19519
  • Bump org.seleniumhq.selenium:htmlunit3-driver from 4.43.0 to 4.45.0 #​19365
  • Bump org.seleniumhq.selenium:selenium-java from 4.43.0 to 4.45.0 #​19344
  • Bump tools.jackson:jackson-bom from 3.2.0 to 3.2.1 #​19438
  • Bump tools.jackson:jackson-bom from 3.2.1 to 3.2.2 #​19562
  • Release 7.1.1 #​19310
  • Upgrade to Micrometer 1.17.1 #​19489
  • Upgrade to Reactor 2025.0.7 #​19488
  • Upgrade to Spring Framework 7.0.9 #​19487
  • Upgrade to Spring LDAP 4.1.1 #​19491
spring-projects/spring-framework (org.springframework:spring-webmvc)

v7.0.9

⚠️ Attention Required

  • In Spring Framework 7.0.9, ForwardedHeaderFilter (Spring MVC) and ForwardedHeaderTransformer (WebFlux) each provide a boolean constructor argument whether to use the standard "Forwarded" header or the "X-Forwarded" alternative headers. A separate property turns on and off use of "X-Forwarded-Prefix". While the default constructor preserves the existing behavior, we recommend to use the new constructor to explicitly specify which forwarded headers to use to make the processing more deterministic and aligned with what is expected from the proxy. Please, see the updated Security Considerations section for details. In 7.1 with #​37072 the default constructor is deprecated and marked for removal. #​37090
  • In Spring Framework 7.0.9, SimpleEvaluationContext no longer supports expression compilation by default, regardless of the compiler mode configured via SpelParserConfiguration or the spring.expression.compiler.mode system property or Spring property. Applications that intentionally use SimpleEvaluationContext with trusted expressions and require compilation for performance reasons can opt in by calling withCompilationSupported() on the SimpleEvaluationContext builder. Care should be taken when opting in to compilation, as doing so removes the safety guards applied during interpreted evaluation. #​37035

⭐ New Features

  • Ignore an empty port value in URI parsing #​37117
  • Avoid retaining class files in annotation metadata #​37112
  • Add @Nullable annotations when treating Map.remove() as returning @Nullable #​37067
  • Revisit SSE view fragments handling #​37061
  • Check list index after auto-grow in AbstractNestablePropertyAccessor #​37036
  • Disable SpEL expression compilation by default in SimpleEvaluationContext #​37035
  • Limit result size of BigDecimal/BigInteger power operations in SpEL #​37034
  • Refactor redirect handling in UrlHandlerFilter #​37030
  • Revise stylesheet source handling in XsltView #​37029
  • Revise view name handling in UrlFilenameViewController #​37027
  • Handle pre-flight requests in functional endpoint setup without DispatcherHandler #​37024
  • Improve WebSocket handshake error logging #​37023
  • Fix missing nullability in JdbcTemplate.batchUpdate #​37012
  • Timeout property in RetryPolicy does not have a default constant #​36983
  • Write native configuration files as UTF-8 #​36972
  • DefaultServerRequest.ServletParametersMap.entrySet() does not retain HttpServletRequest.getParameterMap() order #​36966
  • Perform nextKey within synchronization for SQLite as well #​36959
  • Add support for custom ObjectInputFilter on DefaultDeserializer #​36958
  • Revise resource bundle caching for common locales #​36957
  • Improve nullability for getSession(*) in MockHttpServletRequest #​36926
  • Improve fallback logic in ParameterContentNegotiationStrategy and ParameterContentTypeResolver #​36925
  • Improve ambiguous match check on preflight request #​36903
  • Improve Groovy markup template loading #​36902
  • Improve request path handling on a Reactor Netty server #​36893
  • Improve JettyWebSocketSession error handling #​36891

🐞 Bug Fixes

  • EclipseLinkJpaDialect singleton lock in EclipseLinkConnectionHandle.getConnection() serializes all JDBC connection acquisitions under load #​37085
  • MetadataReader fails to read byte[] array from annotation #​37083
  • Ensure parsing/tostring symmetry in ContentDisposition #​37064
  • Character outside of permitted range in Content Disposition #​37062
  • Release Jackson BufferRecycler to its pool in encoders #​37059
  • Ensure consistent error escaping #​37055
  • Refine template name processing #​37054
  • Reset TwoByteMatcher partial match on mismatching byte #​37053
  • Refactor async XML parsing limit checks #​37031
  • Fix part constraint checks in PartEventHttpMessageReader #​37028
  • Fix buffer leak in RSocket SETUP frame handling #​37026
  • Ensure correct Jetty core response cookie handling #​37025
  • Align domainToAscii with current WhatWG spec #​37018
  • Ensure consistent ButtonTag value attribute processing #​37017
  • SpEL's InlineList is cached as a mutable list in compiled mode #​37001
  • Write native configuration file when only lambda hints are present #​36989
  • SpEL Indexer reuses invalid cached PropertyAccessor #​36986
  • SpEL reuses invalid cached ConstructorExecutor #​36985
  • MimeTypeUtils raises StringIndexOutOfBoundsException for some invalid mime types #​36971
  • Ignore DOCTYPE inside a multi-line comment body #​36948
  • Avoid divide-by-zero in ExponentialBackOff jitter #​36932
  • Refactor use or close lock in ConcurrentWebSocketSessionDecorator #​36909
  • Host header initialization breaking change in StompRelayMessageBrokerHandler #​36907
  • Remote address checks for SockJS session #​36681 breaks xhr-polling #​36904
  • LifeCyclePrintWriter does not delegate correctly #​36885
  • IllegalArgumentException when creating named native query via Shared EntityManager with Hibernate 8.0.0-SNAPSHOT / JPA 4.0.0-M4 #​36878

📔 Documentation

  • Document AOP proxy semantics for Bean Overrides in tests #​37121
  • Provide guidance for object model design in SpEL #​37102
  • Fix Javadoc error in ProtobufDecoder #​37079
  • Document security implications of evaluating untrusted SpEL expressions #​36997
  • Document relationships between expressions, evaluation contexts, and accessors in SpEL #​36968
  • Update Javadoc for @ActiveProfiles ordering #​36950
  • Document behavior for 0 delay combined with jitter in backoff policies #​36946
  • Clarify design goal of UrlFilenameViewController in Javadoc #​36906

🔨 Dependency Upgrades

  • Upgrade to Micrometer 1.16.7 and Tracing 1.6.7 #​37104
  • Upgrade to Reactor 2025.0.7 #​37103

❤️ Contributors

Thank you to all the contributors who worked on this release:

@​ZaMan0806, @​alexisgra, @​alshain, @​gianmarcoschifone, @​junhyeong9812, @​msridhar, @​perovic, @​quaff, and @​samueldlightfoot

JodaOrg/joda-time (joda-time:joda-time)

v2.14.3

Compare Source

See the change notes for more information.

What's Changed

Full Changelog: JodaOrg/joda-time@v2.14.2...v2.14.3

Jaspersoft/jasperreports (net.sf.jasperreports:jasperreports-pdf)

v7.0.8

Compare Source

  • introducing configuration properties to disable query executers and also disable dynamic
    queries that make use of $P!{} parameter references;

  • introducing HTML hyperlink whitelist filter for controlling remote website access from HTML exports;

  • the PDF tagging code has been isolated into a new PdfTagger interface and its latest and
    most complete implementation has been moved out of the JasperReports Library Community Edition
    code base and will only be available as part of the JasperReports Library Professional extensions
    provided by Jaspersoft; Note that PDF tagging functionality is used to produce accessible PDF
    documents (PDF/UA) and PDF documents for archiving (PDF/A);

  • JasperReports can now run on stock OpenPDF 1.3.43; the Jaspersoft build of OpenPDF is only
    required for the PDF/UA link annotation /StructParent tagging, which is otherwise skipped;

  • various dependencies upgrades including: Spring 6.2.19 and Jackson 2.18.8;

  • minor bug fixes and improvements;

vladmihalcea/hypersistence-utils (io.hypersistence:hypersistence-utils-hibernate-63)

v3.15.5

================================================================================

Add support for batching the updateAll methods #​862

Undeprecate ListArrayType #​861

Add support for the PostgreSQL macaddr type #​858

hibernate/hibernate-orm (org.hibernate:hibernate-core)

v6.6.56.Final

v6.6.55.Final


Configuration

📅 Schedule: (in timezone Europe/Zurich)

  • Branch creation
    • "after 5pm on the first day of the month,on the first day of the month"
  • Automerge
    • At any time (no schedule defined)

🚦 Automerge: Enabled.

Rebasing: Whenever PR becomes conflicted, or you tick the rebase/retry checkbox.

👻 Immortal: This PR will be recreated if closed unmerged. Get config help if that's undesired.


  • If you want to rebase/retry this PR, check this box

This PR was generated by Mend Renovate. View the repository job log.

@renovate renovate Bot added the dependencies Update the dependencies label Sep 1, 2026
@renovate
renovate Bot enabled auto-merge (squash) September 1, 2026 00:36
@renovate
renovate Bot force-pushed the renovate/4.0-all-patchminor-versions branch from 55b2a31 to 129bf50 Compare September 2, 2026 02:12
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

dependencies Update the dependencies

Projects

None yet

Development

Successfully merging this pull request may close these issues.

0 participants