Search...
Toggle theme

Release Notes

Complete Changelog for all NES for Spring projects

Spring AMQP

2.4.18 (NES) - November 15, 2024

Notes

  • This release originates from the open-source Spring AMQP repository forked by HeroDevs. It encompasses modifications implemented by HeroDevs to ensure successful framework builds. This release contains no functional changes from Spring AMQP build 2.4.17.
  • Full Version: 2.4.17-spring-amqp-2.4.18

Spring Batch

4.3.11 (NES) - October 21, 2024

Notes

  • This release originates from the open-source Spring Batch repository forked by HeroDevs. It encompasses modifications implemented by HeroDevs to ensure successful framework builds. This release contains no functional changes from Spring Batch build 4.3.10.
  • Full Version: 4.3.10-spring-batch-4.3.11

Spring Boot

2.7.20 (NES) - September 25, 2024

Bug Fixes

  • Addresses issue in Spring Boot Jar loader to detect signature mismatch of nested jar files.
    • This patches the signature forgery vulnerability in Spring Boot's jar loader (CVE-2024-38807).
    • This fix is included in NES for Spring Boot version 2.7.18-spring-boot-2.7.20 in the following artifacts:
      • com.herodevs.nes.springframework.boot:spring-boot-loader:2.7.18-spring-boot-2.7.20

Notes

  • Full Version: 2.7.18-spring-boot-2.7.20

2.7.19 (NES) - August 26, 2024

Notes

  • This release originates from the open-source Spring Boot repository forked by HeroDevs. This release updates Spring Framework to version NES version 5.3.40 and Spring Security NES version 5.7.13.
  • The original Spring Boot 2.7.18 version included the following versions:
  • With the upgrade to our NES versions of Spring Framework 5.3.40 and Spring Security 5.7.13, these include the following changes from both Spring Framework and Spring Security projects. The release notes for those releases are listed below for reference:
  • Includes other modifications implemented by HeroDevs to ensure successful library builds.
  • This release contains no functional changes from Spring Boot 2.7.18.
  • Full Version: 2.7.18-spring-boot-2.7.19

1.5.23 (NES) - November 27, 2024

Notes

  • This is the initial release of Spring Boot 1.5.22 from the open-source Spring Boot repository forked by HeroDevs.
  • This release contains no functional changes from Spring Boot 1.5.22.
  • Full Version: 1.5.22-spring-boot-1.5.23

Spring Data BOM

2.7.19 (NES) - August 30, 2024

Notes

  • This release originates from the open-source Spring Data BOM repository forked by HeroDevs. It encompasses modifications implemented by HeroDevs to ensure successful framework builds. This release contains no functional changes from Spring Data Build 2.7.18.
  • Full Version: 2021.2.18-spring-data-bom-2021.2.19

Spring Data Build

2.7.19 (NES) - August 30, 2024

Notes

  • This release originates from the open-source Spring Data Build repository forked by HeroDevs. It encompasses modifications implemented by HeroDevs to ensure successful framework builds. This release contains no functional changes from Spring Data Build 2.7.18.
  • Full Version: 2.7.18-spring-data-build-2.7.19

Spring Data Cassandra

3.4.19 (NES) - October 11, 2024

Notes

  • This release originates from the open-source Spring Data for Apache Cassandra repository forked by HeroDevs. It encompasses modifications implemented by HeroDevs to ensure successful framework builds. This release contains no functional changes from Spring Data Build 2.7.18.
  • Full Version: 3.4.18-spring-data-cassandra-3.4.19

Spring Data Commons

2.7.19 (NES) - August 30, 2024

Notes

  • This release originates from the open-source Spring Data Commons repository forked by HeroDevs. It encompasses modifications implemented by HeroDevs to ensure successful framework builds. This release contains no functional changes from Spring Data Build 2.7.18.
  • Full Version: 2.7.18-spring-data-commons-2.7.19

Spring Data Couchbase

4.4.19 (NES) - October 11, 2024

Notes

  • This release originates from the open-source Spring Data Couchbase repository forked by HeroDevs. It encompasses modifications implemented by HeroDevs to ensure successful framework builds. This release contains no functional changes from Spring Data Build 2.7.18.
  • Full Version: 4.4.18-spring-data-couchbase-4.4.19

Spring Data Elasticsearch

4.4.19 (NES) - October 11, 2024

Notes

  • This release originates from the open-source Spring Data for Elasticsearch repository forked by HeroDevs. It encompasses modifications implemented by HeroDevs to ensure successful framework builds. This release contains no functional changes from Spring Data Build 2.7.18.
  • Full Version: 4.4.18-spring-data-elasticsearch-4.4.19

Spring Data Envers

2.7.19 (NES) - October 11, 2024

Notes

  • This release originates from the open-source Spring Data Envers repository forked by HeroDevs. It encompasses modifications implemented by HeroDevs to ensure successful framework builds. This release contains no functional changes from Spring Data Build 2.7.18.
  • Full Version: 2.7.18-spring-data-envers-2.7.19

Spring Data JPA

2.7.19 (NES) - August 30, 2024

Notes

  • This release originates from the open-source Spring Data JPA repository forked by HeroDevs. It encompasses modifications implemented by HeroDevs to ensure successful framework builds. This release contains no functional changes from Spring Data Build 2.7.18.
  • Full Version: 2.7.18-spring-data-jpa-2.7.19

Spring Data KeyValue

2.7.19 (NES) - September 27, 2024

Notes

  • This release originates from the open-source Spring Data KeyValue repository forked by HeroDevs. It encompasses modifications implemented by HeroDevs to ensure successful framework builds. This release contains no functional changes from Spring Data Build 2.7.18.
  • Full Version: 2.7.18-spring-data-keyvalue-2.7.19

Spring Data LDAP

2.7.19 (NES) - September 20, 2024

Notes

  • This release originates from the open-source Spring Data LDAP repository forked by HeroDevs. It encompasses modifications implemented by HeroDevs to ensure successful framework builds. This release contains no functional changes from Spring Data Build 2.7.18.
  • Full Version: 2.7.18-spring-data-ldap-2.7.19

Spring Data MongoDB

3.4.19 (NES) - September 27, 2024

Notes

  • This release originates from the open-source Spring Data MongoDB repository forked by HeroDevs. It encompasses modifications implemented by HeroDevs to ensure successful framework builds. This release contains no functional changes from Spring Data Build 2.7.18.
  • Full Version: 3.4.18-spring-data-mongodb-3.4.19

Spring Data Neo4j

6.3.19 (NES) - October 11, 2024

Notes

  • This release originates from the open-source Spring Data Neo4j repository forked by HeroDevs. It encompasses modifications implemented by HeroDevs to ensure successful framework builds. This release contains no functional changes from Spring Data Build 2.7.18.
  • Full Version: 6.3.18-spring-data-neo4j-6.3.19

Spring Data R2DBC

1.5.19 (NES) - September 27, 2024

Notes

  • This release originates from the open-source Spring Data R2DBC repository forked by HeroDevs. It encompasses modifications implemented by HeroDevs to ensure successful framework builds. This release contains no functional changes from Spring Data Build 2.7.18.
  • Full Version: 1.5.18-spring-data-r2dbc-1.5.19

Spring Data Redis

2.7.19 (NES) - September 27, 2024

Notes

  • This release originates from the open-source Spring Data Redis repository forked by HeroDevs. It encompasses modifications implemented by HeroDevs to ensure successful framework builds. This release contains no functional changes from Spring Data Build 2.7.18.
  • Full Version: 2.7.18-spring-data-redis-2.7.19

Spring Data Relational

2.4.19 (NES) - September 20, 2024

Notes

  • This release originates from the open-source Spring Data Relational repository forked by HeroDevs. It encompasses modifications implemented by HeroDevs to ensure successful framework builds. This release contains no functional changes from Spring Data Build 2.7.18.
  • Full Version: 2.4.18-spring-data-relational-2.4.19

Spring Data REST

3.7.19 (NES) - November 12, 2024

Notes

  • This release originates from the open-source Spring Data REST repository forked by HeroDevs. It encompasses modifications implemented by HeroDevs to ensure successful library builds. This release contains no functional changes from Spring Data REST 3.7.18.
  • Full Version: 3.7.18-spring-data-rest-3.7.19

Spring Framework

5.3.44 (NES) - November 15, 2024

Bug Fixes

  • Fixes to core and web packages to address DoS issue.
    • This patches DoS via Spring MVC controller method with byte parameter (CVE-2024-38828).
    • This fix is included in NES for Spring Framework version 5.3.39-spring-framework-5.3.44 in the following artifacts:
      • com.herodevs.nes.springframework:spring-core:5.3.39-spring-framework-5.3.44
      • com.herodevs.nes.springframework:spring-web:5.3.39-spring-framework-5.3.44

Notes

  • Full Version: 5.3.39-spring-framework-5.3.44

5.3.43 (NES) - October 30, 2024

Bug Fixes

  • Fixes to resource handling for Spring's WebMVC.fn and WebFlux.fn (functional) endpoints.
    • This patches a variation of the path traversal vulnerability in Spring's functional web frameworks (CVE-2024-38819).
    • This fix is included in NES for Spring Framework version 5.3.39-spring-framework-5.3.43 in the following artifacts:
      • com.herodevs.nes.springframework:spring-webmvc:5.3.39-spring-framework-5.3.43
      • com.herodevs.nes.springframework:spring-webflux:5.3.39-spring-framework-5.3.43

Notes

  • Full Version: 5.3.39-spring-framework-5.3.43

5.3.42 (NES) - October 24, 2024

Bug Fixes

  • Fixed an issue with DataBinder's disallowedFields related to case insensitivity.
    • This update addresses the Spring Framework DataBinder Case Sensitive Match Exception (CVE-2024-38820).
    • This fix is included in NES for Spring Framework version 5.3.39-spring-framework-5.3.42 in the following artifacts:
      • com.herodevs.nes.springframework:spring-context:5.3.39-spring-framework-5.3.42
      • com.herodevs.nes.springframework:spring-core:5.3.39-spring-framework-5.3.42
      • com.herodevs.nes.springframework:spring-web:5.3.39-spring-framework-5.3.42
      • com.herodevs.nes.springframework:spring-webmvc:5.3.39-spring-framework-5.3.42
      • com.herodevs.nes.springframework:spring-webflux:5.3.39-spring-framework-5.3.42
      • com.herodevs.nes.springframework:spring-websocket:5.3.39-spring-framework-5.3.42

Notes

  • Full Version: 5.3.39-spring-framework-5.3.42

5.3.41 (NES) - September 19, 2024

Bug Fixes

  • Fixes to resource handling for Spring's WebMVC.fn and WebFlux.fn (functional) endpoints.
    • This patches the path traversal vulnerability in Spring's functional web frameworks (CVE-2024-38816).
    • This fix is included in NES for Spring Framework version 5.3.39-spring-framework-5.3.41 in the following artifacts:
      • com.herodevs.nes.springframework:spring-webmvc:5.3.39-spring-framework-5.3.41
      • com.herodevs.nes.springframework:spring-webflux:5.3.39-spring-framework-5.3.41

Notes

  • Full Version: 5.3.39-spring-framework-5.3.41

5.3.40 (NES) - August 26, 2024

Notes

  • This release originates from the open-source Spring Framework repository forked by HeroDevs. It encompasses modifications implemented by HeroDevs to ensure successful framework builds. This release contains no functional changes from Spring Framework 5.3.39.
  • Full Version: 5.3.39-spring-framework-5.3.40

4.3.31 (NES) - November 18, 2024

Notes

  • This is the initial release of Spring Framework 4.3.30 from the open-source Spring Framework repository forked by HeroDevs.
  • This release contains no functional changes from Spring Framework 4.3.30.
  • Full Version: 4.3.30-spring-framework-4.3.31

Spring Hateoas

1.5.6 (NES) - November 12, 2024

Notes

  • This release originates from the open-source Spring Hateoas repository forked by HeroDevs. It encompasses modifications implemented by HeroDevs to ensure successful library builds. This release contains no functional changes from Spring Hateoas 1.5.6.
  • Full Version: 1.5.6-spring-hateoas-1.5.7

Spring Integration

5.5.21 (NES) - November 15, 2024

Notes

  • This release originates from the open-source Spring Integration repository forked by HeroDevs. It encompasses modifications implemented by HeroDevs to ensure successful framework builds. This release contains no functional changes from Spring Integration build 5.5.20.
  • Full Version: 5.5.20-spring-integration-5.5.21

Spring Kafka

2.9.14 (NES) - November 15, 2024

Notes

  • This release originates from the open-source Spring Kafka repository forked by HeroDevs. It encompasses modifications implemented by HeroDevs to ensure successful framework builds. This release contains no functional changes from Spring Kafka build 2.9.13.
  • Full Version: 2.9.13-spring-kafka-2.9.14

Spring LDAP

2.4.5 (NES) - November 20, 2024

Notes

2.4.2 (NES) - August 30, 2024

Notes

  • This release originates from the open-source Spring LDAP repository forked by HeroDevs. It encompasses modifications implemented by HeroDevs to ensure successful framework builds. This release contains no functional changes from Spring Data Build 2.7.18.
  • Full Version: 2.4.1-spring-ldap-2.4.2

Spring Retry

1.3.5 (NES) - October 11, 2024

Notes

  • This release originates from the open-source Spring Retry repository forked by HeroDevs. It encompasses modifications implemented by HeroDevs to ensure successful framework builds. This release contains no functional changes from Spring Retry build 1.3.4.
  • Full Version: 1.3.4-spring-retry-1.3.5

Spring Security

5.8.17 (NES) - November 19, 2024

Bug Fixes

  • This patches the Spring Security Authorization Bypass for Case Sensitive Comparisons (CVE-2024-38827).
    • com.herodevs.nes.springframework.security:spring-security-cas:5.8.16-spring-security-5.8.17
    • com.herodevs.nes.springframework.security:spring-security-config:5.8.16-spring-security-5.8.17
    • com.herodevs.nes.springframework.security:spring-security-core:5.8.16-spring-security-5.8.17
    • com.herodevs.nes.springframework.security:spring-security-crypto:5.8.16-spring-security-5.8.17
    • com.herodevs.nes.springframework.security:spring-security-data:5.8.16-spring-security-5.8.17
    • com.herodevs.nes.springframework.security:spring-security-ldap:5.8.16-spring-security-5.8.17
    • com.herodevs.nes.springframework.security:spring-security-oauth2-client:5.8.16-spring-security-5.8.17
    • com.herodevs.nes.springframework.security:spring-security-taglibs:5.8.16-spring-security-5.8.17
    • com.herodevs.nes.springframework.security:spring-security-web:5.8.16-spring-security-5.8.17

Notes

  • Full Version: 5.8.16-spring-security-5.8.17

5.8.16 (NES) - October 29, 2024

Bug Fixes

  • This patches the Authorization Bypass of Static Resources in WebFlux Applications (CVE-2024-38821).
    • com.herodevs.nes.springframework.security:spring-security-web:5.8.15-spring-security-5.8.16

Notes

  • Full Version: 5.8.15-spring-security-5.8.16

5.8.15 (NES) - September 20, 2024

Notes

  • This release originates from the open-source Spring Security repository forked by HeroDevs starting with version 5.8.14.
  • Includes other modifications implemented by HeroDevs to ensure successful library builds.
  • Full Version: 5.8.14-spring-security-5.8.15

5.7.15 (NES) - November 19, 2024

Bug Fixes

  • This patches the Spring Security Authorization Bypass for Case Sensitive Comparisons (CVE-2024-38827).
    • com.herodevs.nes.springframework.security:spring-security-cas:5.7.14-spring-security-5.7.15
    • com.herodevs.nes.springframework.security:spring-security-config:5.7.14-spring-security-5.7.15
    • com.herodevs.nes.springframework.security:spring-security-core:5.7.14-spring-security-5.7.15
    • com.herodevs.nes.springframework.security:spring-security-crypto:5.7.14-spring-security-5.7.15
    • com.herodevs.nes.springframework.security:spring-security-data:5.7.14-spring-security-5.7.15
    • com.herodevs.nes.springframework.security:spring-security-ldap:5.7.14-spring-security-5.7.15
    • com.herodevs.nes.springframework.security:spring-security-oauth2-client:5.7.14-spring-security-5.7.15
    • com.herodevs.nes.springframework.security:spring-security-taglibs:5.7.14-spring-security-5.7.15
    • com.herodevs.nes.springframework.security:spring-security-web:5.7.14-spring-security-5.7.15

Notes

  • Full Version: 5.7.14-spring-security-5.7.15

5.7.14 (NES) - October 29, 2024

Bug Fixes

  • This patches the Authorization Bypass of Static Resources in WebFlux Applications (CVE-2024-38821).
    • com.herodevs.nes.springframework.security:spring-security-web:5.7.13-spring-security-5.7.14

Notes

  • Full Version: 5.7.13-spring-security-5.7.14

5.7.13 (NES) - August 26, 2024

Notes

  • This release originates from the open-source Spring Security repository forked by HeroDevs starting with version 5.7.12.
  • Includes other modifications implemented by HeroDevs to ensure successful library builds.
  • Spring Security 5.7.12 includes Spring Framework 5.3.29. This release updates Spring Framework to version NES version 5.3.40 which is equivalent to the original Spring Framework 5.3.39. For reference, here is a list of all included updates from Spring Framework included here:
    • v5.3.30
    • v5.3.31
    • v5.3.32
    • v5.3.33
    • v5.3.34
    • v5.3.35
    • v5.3.36
    • v5.3.37
    • v5.3.38
    • v5.3.39
  • Full Version: 5.7.12-spring-security-5.7.13

4.2.21 (NES) - November 7, 2024

Notes

  • This is the initial release of Spring Security 4.2.20 from the open-source Spring Security repository forked by HeroDevs.
  • This release contains no functional changes from Spring Security 4.2.20.
  • Full Version: 4.2.20-spring-security-4.2.21

Spring Session

2.7.5 (NES) - October 28, 2024

Notes

  • This release originates from the open-source Spring Session repository forked by HeroDevs. It encompasses modifications implemented by HeroDevs to ensure successful library builds. This release contains no functional changes from Spring Session 2.7.4.
  • Full Version: 2.7.4-spring-session-2.7.5

Spring-WS

3.1.9 (NES) - October 15, 2024

Notes

  • This release originates from the open-source Spring Web Services (Spring-WS) repository forked by HeroDevs. It encompasses modifications implemented by HeroDevs to ensure successful library builds. This release contains no functional changes from Spring WS 3.1.8.
  • Full Version: 3.1.8-spring-ws-3.1.9

Dozer

5.5.2 (NES) - September 5, 2024

Notes

  • This release originates from the open-source DozerMapper project forked by HeroDevs. It encompasses modifications implemented by HeroDevs to ensure successful framework builds.
  • This release contains no functional changes from DozerMapper version 5.5.1.
  • Full Version: 5.5.1-dozer-5.5.2

MyBatis Parent

33.0.1 (NES) - September 5, 2024

Notes

  • This release originates from the open-source MyBatis Parent project forked by HeroDevs. It encompasses modifications implemented by HeroDevs to ensure successful framework builds.
  • This release contains no functional changes from MyBatis Parent version 33.
  • Full Version: 33.0.0-mybatis-parent-33.0.1

MyBatis Spring

2.0.8 (NES) - September 5, 2024

Notes

  • This release originates from the open-source MyBatis Spring project forked by HeroDevs. It encompasses modifications implemented by HeroDevs to ensure successful framework builds.
  • This release contains no functional changes from MyBatis Spring version 2.0.7.
  • Full Version: 2.0.7-mybatis-spring-2.0.8

SpringDoc OpenAPI

1.7.1 (NES) - September 5, 2024

Notes

  • This release originates from the open-source SpringDoc OpenAPI project forked by HeroDevs. It encompasses modifications implemented by HeroDevs to ensure successful framework builds.
  • This release contains no functional changes from SpringDoc OpenAPI version 1.7.0.
  • Full Version: 1.7.0-springdoc-openapi-1.7.1

Struts

2.5.34 (NES) - September 5, 2024

Notes

  • This release originates from the open-source Struts project forked by HeroDevs. It encompasses modifications implemented by HeroDevs to ensure successful framework builds.
  • This release contains no functional changes from Struts version 2.5.33.
  • Full Version: 2.5.33-struts2-2.5.34

Struts Parent

14.0.1 (NES) - September 5, 2024

Notes

  • This release originates from the open-source Struts Master forked by HeroDevs. It encompasses modifications implemented by HeroDevs to ensure successful framework builds.
  • This release contains no functional changes from Struts Master 14.
  • Full Version: 14.0.0-struts-master-14.0.1