Spring Framework CVE-2024-38819 and CVE-2024-38820 published

Releases | Brian Clozel | October 17, 2024 | ...

The Spring Framework has released version 6.1.14 that contains a fix for both:

  • CVE-2024-38819: Path traversal vulnerability in functional web frameworks (2nd report)
  • CVE-2024-38820: Spring Framework DataBinder case sensitive match exception

Note that open source support for Spring Framework 5.3.x and 6.0.x generations has ended last August, as announced previously. This fix has been applied to the 5.3.41 and 6.0.25 commercial releases, available now.

If you are not a commercial customer, please consider upgrading to an open source supported version at your earliest convenience.

Upgrading…

Spring Tools 4.26.0 released

Releases | Martin Lippert | October 17, 2024 | ...

Dear Spring Community,

I am happy to announce the 4.26.0 release of the Spring Tools 4 for Visual Studio Code, Eclipse and Theia.

important highlights

  • (Spring Boot) CRON expressions have auto completion and a nice description as inlay hints now
  • (Spring Boot) @ConditionalOnBean and @ConditinalOnMissingBean have auto completion support now for bean names, including support for go to definition
  • (Spring Boot) support for go to definition for beans and methods in SPEL expressions
  • (Spring Boot) Improvements to completion proposals ordering for application.properties files
  • (Spring Boot) Fixes to PostgreSql validation

Spring Framework 6.2.0-RC2 available now

Releases | Brian Clozel | October 17, 2024 | ...

We are happy to announce the availability of the second release candidate of Spring Framework 6.2. We have been working on fixing regressions from previous milestones and shipping performance improvements.

Spring Framework 6.2.0-RC2 is available from repo.spring.io/milestone now, check out the detailed changelog for this version.

Spring 3.4.0-RC1 will be released next week, a good opportunity for testing the upcoming Spring generation in existing applications!

6.2 features recap

Check out our What's New page for details about the new features available at this point.

This Week in Spring - October 15th, 2024

Engineering | Josh Long | October 15, 2024 | ...

Hi, Spring fans! Welcome to another rip-roaring and ever-so-riveting installment of This Week in Spring! I'm in Amsterdam, at the moment, rounding out a week between Antwerp, Beglium, and Amsterdam, the Netherlands. Today I'm off to Dubai for the fantastic GITEX/DevSlam event. Then I return back to Europe for Voxxed Days Thessaloniki, in Greece. Should be a fun week!

It's certainly been a fun week! Let's dive right into it!

Spring Batch 5.2.0-M2 is available now!

Releases | Mahmoud Ben Hassine | October 11, 2024 | ...

I am pleased to announce that the second milestone of Spring Batch 5.2 is now available from our milestones repository. This blog post walks you through the main changes in Spring Batch 5.2:

  • MongoDB job repository support
  • New resourceless job repository
  • Composite item reader implementation
  • New adapters for java.util.function APIs
  • Concurrent steps with blocking queue item reader and writer

For the complete list of changes, please check the release notes.

MongoDB job repository support

This release introduces the first NoSQL job repository implementation which is backed by MongoDB. Similar to…

Spring Cloud 2024.0.0-M2 (aka Moorgate) Has Been Released

Releases | Ryan Baxter | October 09, 2024 | ...

On behalf of the community, I am pleased to announce that the Milestone 2 (M2) of the Spring Cloud 2024.0.0 Release Train is available today. The release can be found in Spring Milestone repository. You can check out the 2024.0.0 release notes for more information.

Notable Changes in the 2024.0.0-M2 Release Train

This release of Spring Cloud is based on Spring Boot 3.4.0-M3.

The GitHub project for this release can be found here.

Spring Cloud OpenFeign

  • Support ignorecase with Pageable (#1047)

Spring Cloud Commons

  • Create a TrustStore without requiring a KeyStore (#1394)

Spring Cloud Config

  • Resources can be stored and received with a given charset (#2115)
  • Add MongoDB environment repository support (#2390)
  • Support Multiple Labels In Environment Repositories (#2449)

This Week in Spring - October 8th, 2024

Engineering | Josh Long | October 08, 2024 | ...

Hi, Spring fans! Welcome to another installment of This Week in Spring! I'm in Antwerp, Belgium, for the amazing Devoxx Belgium 2024 event! I am so happy to be back here, one of the best shows in the Java ecosystem!

We've got a lot to get into so let's dive right in!

Get the Spring newsletter

Stay connected with the Spring newsletter

Subscribe

Get ahead

VMware offers training and certification to turbo-charge your progress.

Learn more

Get support

Tanzu Spring offers support and binaries for OpenJDK™, Spring, and Apache Tomcat® in one simple subscription.

Learn more

Upcoming events

Check out all the upcoming events in the Spring community.

View all