Announcing nohttp

Engineering | Rob Winch | June 10, 2019 | ...

I’m pleased to announce the nohttp project, which lets users find, replace, and prevent the usage of http://.

Background

Today, Jonathan Leitschuh published a blog titled Want to take over the Java ecosystem? All you need is a MITM!. The blog demonstrates that hundreds of Java libraries are downloading dependencies over HTTP. This opens the projects up to potential MITM (man in the middle) attacks.

Unfortunately, there were multiple Spring projects that were using HTTP to download dependencies. Fortunately, we uncovered no signs of a successful MITM attack. We have also addressed the issue to…

This Week in Spring - June 11th, 2019

Engineering | Josh Long | June 10, 2019 | ...

Hi Spring fans! Can you believe it? We're already almost halfway through June! Summer's nearly here! It's 97 Fahrenheit / 37 Celsius in San Francisco! That's nuts! I'm glad I'm in beautiful Amsterdam and Eindhoven, NL, beating the heat, though. What a privilege. We've got a busy week, as always, to get to so let's get to it!

This Week in Spring - June 4, 2019

Engineering | Josh Long | June 04, 2019 | ...

Hi Spring fans! Welcome to another installment of This Week in Spring! This week I'm in.... I'm home! Look at that! I'm home for the epic SpringOne Tour San Francisco event. I'm super excited to be here in this amazing weather with an amazing community. It's been a busy week though! Last week I returned from Spain for my kid's graduation, and I am still so so proud. Tomorrow I fly to Cork, Ireland for the Cork JUG and then it's off to London for a wedding. So, lot of travel, but a bit of a lighter load :-)

We've got a lot to cover so let's get to it!

Introducing Spring Cloud App Broker

Engineering | Roy Clarkson | May 30, 2019 | ...

We recently announced the general availability of Spring Cloud Services 3.0, which involved a major redesign of the previous architecture used in that project. As detailed in the related blog post, Spring Cloud Services has moved to the latest versions of Spring Framework and Spring Boot, and is now built on a Reactive programming model and Spring WebFlux. Two key components of this redesign are offered as open source Spring Cloud projects.

The first project is Spring Cloud Open Service Broker. This project has been available for some time; however, the recent 3.0.0 release has itself been…

Get the Spring newsletter

Stay connected with the Spring newsletter

Subscribe

Get ahead

VMware offers training and certification to turbo-charge your progress.

Learn more

Get support

Tanzu Spring offers support and binaries for OpenJDK™, Spring, and Apache Tomcat® in one simple subscription.

Learn more

Upcoming events

Check out all the upcoming events in the Spring community.

View all