Bump org.springframework.security:spring-security-bom from 6.5.3 to 6.5.4 in /spring
Open
Number: #2328
Type: Pull Request
State: Open
Type: Pull Request
State: Open
Author:
dependabot[bot]
Association: Contributor
Comments: 0
Association: Contributor
Comments: 0
Created:
September 16, 2025 at 05:01 PM UTC
(9 months ago)
(9 months ago)
Updated:
September 16, 2025 at 05:01 PM UTC
(9 months ago)
(9 months ago)
Labels:
backport 1.2
backport 1.2
Description:
Bumps org.springframework.security:spring-security-bom from 6.5.3 to 6.5.4.
Release notes
Sourced from org.springframework.security:spring-security-bom's releases.
6.5.4
:star: New Features
- Update servlet test method docs to use include-code #17749
:beetle: Bug Fixes
- Annonation Scanning Should Fallback to Object when Parameter Matching #17899
- Fix double-slash when basePath is root #17841
- Fix traceId discrepancy in case error in servlet web #17796
- Reference should advise avoiding post-authorization on writes #17798
:hammer: Dependency Upgrades
- Bump com.google.code.gson:gson from 2.13.1 to 2.13.2 #17893
- Bump com.google.code.gson:gson from 2.13.1 to 2.13.2 #17874
- Bump com.webauthn4j:webauthn4j-core from 0.29.5.RELEASE to 0.29.6.RELEASE #17895
- Bump com.webauthn4j:webauthn4j-core from 0.29.5.RELEASE to 0.29.6.RELEASE #17854
- Bump com.webauthn4j:webauthn4j-core from 0.29.5.RELEASE to 0.29.6.RELEASE #17836
- Bump io.micrometer:micrometer-observation from 1.14.10 to 1.14.11 #17894
- Bump io.micrometer:micrometer-observation from 1.14.10 to 1.14.11 #17858
- Bump org.assertj:assertj-core from 3.27.3 to 3.27.4 #17767
- Bump org.hibernate.orm:hibernate-core from 6.6.23.Final to 6.6.26.Final #17766
- Bump org.hibernate.orm:hibernate-core from 6.6.23.Final to 6.6.26.Final #17759
- Bump org.hibernate.orm:hibernate-core from 6.6.26.Final to 6.6.28.Final #17853
- Bump org.hibernate.orm:hibernate-core from 6.6.26.Final to 6.6.28.Final #17837
- Bump org.hibernate.orm:hibernate-core from 6.6.26.Final to 6.6.29.Final #17896
- Bump org.springframework.data:spring-data-bom from 2024.1.8 to 2024.1.10 #17897
- Bump org.springframework.data:spring-data-bom from 2024.1.8 to 2024.1.9 #17855
- Bump org.springframework.data:spring-data-bom from 2024.1.8 to 2024.1.9 #17791
- Bump org.springframework.data:spring-data-bom from 2024.1.8 to 2024.1.9 #17771
- Bump org.springframework.data:spring-data-bom from 2024.1.8 to 2024.1.9 #17758
- Bump org.springframework.ldap:spring-ldap-core from 3.2.13 to 3.2.14 #17773
:heart: Contributors
Thank you to all the contributors who worked on this release:
@jkuheland@therepanic
Commits
1349a73Release 6.5.4d0f93faMerge branch '6.4.x' into 6.5.xe5694acFallback to Object When Determining Overridden Methodsad86ae0Merge branch '6.4.x' into 6.5.x9de0aadAllow patch version updates for nimbus-jose-jwt7293fc0Update to nimbus-jose-jwt:9.37.4f7b380eMerge branch '6.4.x' into 6.5.x94ec064Bump com.google.code.gson:gson from 2.13.1 to 2.13.28b924e9Bump io.micrometer:micrometer-observation from 1.14.10 to 1.14.11e8ace55Bump com.webauthn4j:webauthn4j-core from 0.29.5.RELEASE to 0.29.6.RELEASE- Additional commits viewable in compare view
Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting @dependabot rebase.
Dependabot commands and options
You can trigger Dependabot actions by commenting on this PR:
@dependabot rebasewill rebase this PR@dependabot recreatewill recreate this PR, overwriting any edits that have been made to it@dependabot mergewill merge this PR after your CI passes on it@dependabot squash and mergewill squash and merge this PR after your CI passes on it@dependabot cancel mergewill cancel a previously requested merge and block automerging@dependabot reopenwill reopen this PR if it is closed@dependabot closewill close this PR and stop Dependabot recreating it. You can achieve the same result by closing it manually@dependabot show <dependency name> ignore conditionswill show all of the ignore conditions of the specified dependency@dependabot ignore this major versionwill close this PR and stop Dependabot creating any more for this major version (unless you reopen the PR or upgrade to it yourself)@dependabot ignore this minor versionwill close this PR and stop Dependabot creating any more for this minor version (unless you reopen the PR or upgrade to it yourself)@dependabot ignore this dependencywill close this PR and stop Dependabot creating any more for this dependency (unless you reopen the PR or upgrade to it yourself)
Pull Request Statistics
Commits:
1
1
Files Changed:
1
1
Additions:
+1
+1
Deletions:
-1
-1
Package Dependencies
Ecosystem:
maven
maven
Version Change:
6.5.3 → 6.5.4
Update Type:
Patch
Patch
Path:
/spring
Technical Details
| ID: | 7899738 |
| UUID: | 2833780566 |
| Node ID: | PR_kwDOHloRjM6o6A9W |
| Host: | GitHub |
| Repository: | inrupt/solid-client-java |
| Merge State: | Unknown |