Skip to content

build(deps-dev): Bump org.springframework.security:spring-security-core from 7.0.2 to 7.0.3#2484

Merged
MikeEdgar merged 1 commit intomainfrom
dependabot/maven/org.springframework.security-spring-security-core-7.0.3
Feb 14, 2026
Merged

build(deps-dev): Bump org.springframework.security:spring-security-core from 7.0.2 to 7.0.3#2484
MikeEdgar merged 1 commit intomainfrom
dependabot/maven/org.springframework.security-spring-security-core-7.0.3

Conversation

@dependabot
Copy link
Contributor

@dependabot dependabot bot commented on behalf of github Feb 13, 2026

Bumps org.springframework.security:spring-security-core from 7.0.2 to 7.0.3.

Release notes

Sourced from org.springframework.security:spring-security-core's releases.

7.0.3

⭐ New Features

  • Fix Javadoc warnings in spring-security-web #18473
  • Fix/gradle 9 deprecations #18485
  • Fix/gradle 9 deprecations #18477
  • Replace method call with 'Builder.configureMessageConverters()' #18378
  • Replacing use of deprecated 'check' in authorization documentation #18390
  • Use DefaultParameterNameDiscoverer#getSharedInstance #18481

🪲 Bug Fixes

  • Authorization Server fails to start with multiple PasswordEncoder beans #18645
  • BearerTokenAuthenticationEntryPoint uses context path #18528
  • Create SHA-1 MessageDigest for every new check request in Compromised Password Checker #18594
  • Document Client PKCE settings #18304
  • Fix docs typo X-Requested-By -> X-Requested-With #18123
  • Fix Formatting in mfa.adoc #18134
  • Fix typo in documentation #18344
  • Fix typos #18121

🔨 Dependency Upgrades

  • Bump ch.qos.logback:logback-classic from 1.5.22 to 1.5.24 #18384
  • Bump ch.qos.logback:logback-classic from 1.5.24 to 1.5.28 #18684
  • Bump ch.qos.logback:logback-classic from 1.5.28 to 1.5.29 #18711
  • Bump com.fasterxml.jackson:jackson-bom from 2.20.1 to 2.20.2 #18660
  • Bump com.webauthn4j:webauthn4j-core from 0.29.7.RELEASE to 0.31.0.RELEASE #18687
  • Bump gradle-wrapper from 8.14 to 8.14.4 #18705
  • Bump io.mockk:mockk from 1.14.7 to 1.14.9 #18681
  • Bump io.projectreactor:reactor-bom from 2025.0.1 to 2025.0.2 #18658
  • Bump io.projectreactor:reactor-bom from 2025.0.2 to 2025.0.3 #18717
  • Bump io.spring.develocity.conventions from 0.0.24 to 0.0.25 #18683
  • Bump io.spring.gradle:spring-security-release-plugin from 1.0.13 to 1.0.14 #18725
  • Bump jakarta.xml.bind:jakarta.xml.bind-api from 4.0.4 to 4.0.5 #18706
  • Bump org-apache-maven-resolver from 1.9.24 to 1.9.25 #18309
  • Bump org-aspectj from 1.9.25 to 1.9.25.1 #18326
  • Bump org.apache.httpcomponents.client5:httpclient5 from 5.5.1 to 5.5.2 #18346
  • Bump org.apache.maven:maven-resolver-provider from 3.9.11 to 3.9.12 #18327
  • Bump org.assertj:assertj-core from 3.27.6 to 3.27.7 #18682
  • Bump org.junit:junit-bom from 6.0.1 to 6.0.2 #18385
  • Bump org.springframework.data:spring-data-bom from 2025.1.1 to 2025.1.2 #18655
  • Bump org.springframework.ldap:spring-ldap-core from 4.0.0 to 4.0.1 #18316
  • Bump org.springframework.ldap:spring-ldap-core from 4.0.1 to 4.0.2 #18733
  • Bump org.springframework:spring-framework-bom from 7.0.3 to 7.0.4 #18732
  • Bump org.springframework:spring-framework-bom from 7.0.3-SNAPSHOT to 7.0.4-SNAPSHOT #18657
  • Bump spring-io/spring-doc-actions from 0.0.20 to 0.0.22 #18651
  • Bump tools.jackson:jackson-bom from 3.0.3 to 3.0.4 #18659
  • Update Antora UI Spring to v0.4.25 #18249
  • Update to Spring Framework 7.0.3 #18667

... (truncated)

Commits
  • ffe73b4 Release 7.0.3
  • f0ffda8 Update to spring-data-bom 2025.1.3
  • 746c6e1 Bump org.springframework:spring-framework-bom from 7.0.3 to 7.0.4
  • 123a2d7 Bump io.projectreactor:reactor-bom from 2025.0.2 to 2025.0.3
  • 0c3e483 Bump org.springframework.ldap:spring-ldap-core from 4.0.1 to 4.0.2
  • b804da9 Update Test to Align with webauthn4j
  • b9bb5e0 Bump com.webauthn4j:webauthn4j-core
  • 4fd8e1d Remove Trailing Bytes from AttestationStatement
  • c59fb0c Add Jackson 2 Databind as Optional Dependency
  • 50aba3a Bump io.spring.gradle:spring-security-release-plugin
  • Additional commits viewable in compare view

Dependabot compatibility score

Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting @dependabot rebase.


Dependabot commands and options

You can trigger Dependabot actions by commenting on this PR:

  • @dependabot rebase will rebase this PR
  • @dependabot recreate will recreate this PR, overwriting any edits that have been made to it
  • @dependabot show <dependency name> ignore conditions will show all of the ignore conditions of the specified dependency
  • @dependabot ignore this major version will close this PR and stop Dependabot creating any more for this major version (unless you reopen the PR or upgrade to it yourself)
  • @dependabot ignore this minor version will close this PR and stop Dependabot creating any more for this minor version (unless you reopen the PR or upgrade to it yourself)
  • @dependabot ignore this dependency will close this PR and stop Dependabot creating any more for this dependency (unless you reopen the PR or upgrade to it yourself)

@dependabot dependabot bot added dependencies Pull requests that update a dependency file java Pull requests that update Java code labels Feb 13, 2026
@MikeEdgar MikeEdgar added this to the 4.3.0 milestone Feb 14, 2026
@MikeEdgar MikeEdgar enabled auto-merge (squash) February 14, 2026 11:37
Bumps [org.springframework.security:spring-security-core](https://github.com/spring-projects/spring-security) from 7.0.2 to 7.0.3.
- [Release notes](https://github.com/spring-projects/spring-security/releases)
- [Changelog](https://github.com/spring-projects/spring-security/blob/main/RELEASE.adoc)
- [Commits](spring-projects/spring-security@7.0.2...7.0.3)

---
updated-dependencies:
- dependency-name: org.springframework.security:spring-security-core
  dependency-version: 7.0.3
  dependency-type: direct:development
  update-type: version-update:semver-patch
...

Signed-off-by: dependabot[bot] <support@github.com>
@dependabot dependabot bot force-pushed the dependabot/maven/org.springframework.security-spring-security-core-7.0.3 branch from 0655d00 to b3f27e7 Compare February 14, 2026 11:37
@MikeEdgar MikeEdgar merged commit 5b58558 into main Feb 14, 2026
10 checks passed
@MikeEdgar MikeEdgar deleted the dependabot/maven/org.springframework.security-spring-security-core-7.0.3 branch February 14, 2026 11:48
@sonarqubecloud
Copy link

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

dependencies Pull requests that update a dependency file java Pull requests that update Java code

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant