Bump org.apache.shiro:shiro-core from 1.2.4 to 2.1.0 by dependabot[bot] · Pull Request #19 · Cognia-TestLab/java-sec-code
Bumps org.apache.shiro:shiro-core from 1.2.4 to 2.1.0.
Release notes
Sourced from org.apache.shiro:shiro-core's releases.
Apache Shiro 2.1.0
What's Changed
- chore(deps): bump org.htmlunit:htmlunit from 4.17.0 to 4.18.0 by
@dependabot[bot] in apache/shiro#2355- chore: hide deprecation warning in AD test by
@lprimakin apache/shiro#2352- chore(deps): bump github/codeql-action from 4.31.0 to 4.31.2 in the github-dependencies group by
@dependabot[bot] in apache/shiro#2353- chore(deps): bump bytebuddy.version from 1.17.8 to 1.18.1 by
@dependabot[bot] in apache/shiro#2369- chore(deps): bump org.owasp:dependency-check-maven from 12.1.8 to 12.1.9 by
@dependabot[bot] in apache/shiro#2367- chore(deps): bump org.omnifaces:omnifaces from 3.14.11 to 3.14.12 by
@dependabot[bot] in apache/shiro#2364- #953 - Allow CORS preflight requests to bypass authentication by
@celikfatihin apache/shiro#2372- chore: put back changes that were overwritten by maven release plugin by
@lprimakin apache/shiro#2375- chore(deps): bump bytebuddy.version from 1.18.1 to 1.18.2 by
@dependabot[bot] in apache/shiro#2389- chore(deps): bump org.quartz-scheduler:quartz from 2.5.1 to 2.5.2 by
@dependabot[bot] in apache/shiro#2387- chore(deps): bump org.codehaus.mojo:taglist-maven-plugin from 3.2.1 to 3.2.2 by
@dependabot[bot] in apache/shiro#2380- chore(deps): bump org.codehaus.mojo:versions-maven-plugin from 2.19.1 to 2.20.1 by
@dependabot[bot] in apache/shiro#2379- chore(deps): bump org.htmlunit:htmlunit from 4.18.0 to 4.19.0 by
@dependabot[bot] in apache/shiro#2377- chore(deps): bump org.owasp.encoder:encoder from 1.3.1 to 1.4.0 by
@dependabot[bot] in apache/shiro#2374- chore(deps): bump the github-dependencies group with 2 updates by
@dependabot[bot] in apache/shiro#2373- Configure EditorConfig for
.rdfby@jbamptonin apache/shiro#2386- Remove
typeattributes from HTMLscripttags by@jbamptonin apache/shiro#2382- pre-commit: add 3 more hooks; fix end of files by
@jbamptonin apache/shiro#2360- Pin all actions workflows by
@jbamptonin apache/shiro#2385- Add pre-commit hook to trim trailing whitespace by
@jbamptonin apache/shiro#2406- gha: use pre-commit run
--color=alwaysby@jbamptonin apache/shiro#2407- chore: pin python and it's depenendencies for pre-commit check on GitHub by
@lprimakin apache/shiro#2408- chore: pin python pre-commit workflow dependency with hash by
@lprimakin apache/shiro#2410- Add descriptions to all pre-commit hooks by
@jbamptonin apache/shiro#2409- chore: fix vulnerabilities in tests reported by OpenSSF tool by
@lprimakin apache/shiro#2411- chore(deps): bump org.htmlunit:htmlunit from 4.19.0 to 4.20.0 by
@dependabot[bot] in apache/shiro#2415- chore(deps): bump the github-dependencies group with 5 updates by
@dependabot[bot] in apache/shiro#2414- chore(deps): bump mockito.version from 5.20.0 to 5.21.0 by
@dependabot[bot] in apache/shiro#2420- chore(deps): bump ch.qos.logback:logback-core from 1.5.21 to 1.5.22 by
@dependabot[bot] in apache/shiro#2419- chore(deps): bump ch.qos.logback:logback-classic from 1.5.21 to 1.5.22 by
@dependabot[bot] in apache/shiro#2417- chore(deps): bump the github-dependencies group with 3 updates by
@dependabot[bot] in apache/shiro#2418- chore(security): update log4-core by
@lprimakin apache/shiro#2430- chore(deps): bump org.codehaus.mojo:exec-maven-plugin from 3.6.2 to 3.6.3 by
@dependabot[bot] in apache/shiro#2429- chore(deps): bump ch.qos.logback:logback-core from 1.5.22 to 1.5.23 by
@dependabot[bot] in apache/shiro#2427- chore(deps): bump com.github.siom79.japicmp:japicmp-maven-plugin from 0.24.2 to 0.25.1 by
@dependabot[bot] in apache/shiro#2428- chore(deps): bump github/codeql-action from 4.31.8 to 4.31.9 in the github-dependencies group by
@dependabot[bot] in apache/shiro#2424- chore(deps): bump ch.qos.logback:logback-classic from 1.5.22 to 1.5.23 by
@dependabot[bot] in apache/shiro#2426- chore(deps): bump bytebuddy.version from 1.18.2 to 1.18.3 by
@dependabot[bot] in apache/shiro#2425- chore(deps): bump org.htmlunit:htmlunit from 4.20.0 to 4.21.0 by
@dependabot[bot] in apache/shiro#2431- chore(deps): bump ch.qos.logback:logback-classic from 1.5.23 to 1.5.24 by
@dependabot[bot] in apache/shiro#2455- chore(deps): bump org.owasp:dependency-check-maven from 12.1.9 to 12.2.0 by
@dependabot[bot] in apache/shiro#2454- chore(deps): bump com.github.siom79.japicmp:japicmp-maven-plugin from 0.25.1 to 0.25.4 by
@dependabot[bot] in apache/shiro#2453- chore(deps): bump ch.qos.logback:logback-core from 1.5.23 to 1.5.24 by
@dependabot[bot] in apache/shiro#2452- chore(deps): bump javax.enterprise:cdi-api from 2.0 to 2.0.SP1 by
@dependabot[bot] in apache/shiro#2451- chore(deps): bump org.jsoup:jsoup from 1.21.2 to 1.22.1 by
@dependabot[bot] in apache/shiro#2442- chore(deps): bump github/codeql-action from 4.31.9 to 4.31.10 in the github-dependencies group by
@dependabot[bot] in apache/shiro#2449- #2460 bugfix: avoid duplicate proxying of StoppingAwareProxiedSession by
@lprimakin apache/shiro#2459- #2458 Deploy next snapshot version as computed dynamically from latest release by
@lprimakin apache/shiro#2456
... (truncated)
Changelog
Sourced from org.apache.shiro:shiro-core's changelog.
Licensed to the Apache Software Foundation (ASF) under one
or more contributor license agreements. See the NOTICE file
distributed with this work for additional information
regarding copyright ownership. The ASF licenses this file
to you under the Apache License, Version 2.0 (the
"License"); you may not use this file except in compliance
with the License. You may obtain a copy of the License at
http://www.apache.org/licenses/LICENSE-2.0
Unless required by applicable law or agreed to in writing,
software distributed under the License is distributed on an
"AS IS" BASIS, WITHOUT WARRANTIES OR CONDITIONS OF ANY
KIND, either express or implied. See the License for the
specific language governing permissions and limitations
under the License.
This is not an official release notes document. It exists for Shiro developers to jot down their notes while working in the source code. These notes will be combined with Jira’s auto-generated release notes during a release for the total set.
###########################################################
2.0.0
###########################################################
Improvement
[SHIRO-290] Implement bcrypt and argon2 KDF algorithmsBackwards Incompatible Changes
- Changed default DefaultPasswordService.java algorithm to "Argon2id".
- PasswordService.encryptPassword(Object plaintext) will now throw a NullPointerException on null parameter. It was never specified how this method would behave.
- Made salt non-nullable.
- Removed methods in PasswordMatcher.
###########################################################
1.7.1
###########################################################
Bug
[SHIRO-797] - Shiro 1.7.0 is lower than using springboot version 2.0.7 dependency error###########################################################
... (truncated)
Commits
2b873bc[maven-release-plugin] prepare release shiro-root-2.1.08dc0d81[dependency] Upgrade to Apache POM 373b9638benh: added case-insensitive path filteringf27f46eUpdate pre-commit workflow set--show-diff-on-failure(#2487)87d29dfchore: Eclipse IDE ignores for license checks (#2484)2dfa579Runpre-commit autoupdateto update the hooks (#2486)9266bfaMerge pull request #2475 from lprimak/fix-private-salt-compate9e5e3fMerge pull request #1026 from haster/change-pathtraversal-blockmode4bf410cenh: added test for secret salt with Shiro1 compatibility84b2fdbMerge branch 'main' into fix-private-salt-compat- Additional commits viewable in compare view
Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting @dependabot rebase.
Dependabot commands and options
You can trigger Dependabot actions by commenting on this PR:
@dependabot rebasewill rebase this PR@dependabot recreatewill recreate this PR, overwriting any edits that have been made to it@dependabot show <dependency name> ignore conditionswill show all of the ignore conditions of the specified dependency@dependabot ignore this major versionwill close this PR and stop Dependabot creating any more for this major version (unless you reopen the PR or upgrade to it yourself)@dependabot ignore this minor versionwill close this PR and stop Dependabot creating any more for this minor version (unless you reopen the PR or upgrade to it yourself)@dependabot ignore this dependencywill close this PR and stop Dependabot creating any more for this dependency (unless you reopen the PR or upgrade to it yourself)
You can disable automated security fix PRs for this repo from the Security Alerts page.