You are viewing a plain text version of this content. The canonical link for it is here.
Posted to commits@camel.apache.org by "dependabot[bot] (via GitHub)" <gi...@apache.org> on 2024/02/29 06:52:46 UTC

[PR] Bump org.apache.shiro:shiro-core from 1.13.0 to 2.0.0 [camel]

dependabot[bot] opened a new pull request, #13344:
URL: https://github.com/apache/camel/pull/13344

   Bumps [org.apache.shiro:shiro-core](https://github.com/apache/shiro) from 1.13.0 to 2.0.0.
   <details>
   <summary>Release notes</summary>
   <p><em>Sourced from <a href="https://github.com/apache/shiro/releases">org.apache.shiro:shiro-core's releases</a>.</em></p>
   <blockquote>
   <h2>Apache Shiro 2.0.0</h2>
   <h2>What's new Highlights</h2>
   <ul>
   <li>Java 11 is the minimum supported JVM version</li>
   <li>Jakarta EE 10 support (Java/Jakarta EE 8 is also supported)</li>
   <li>New Jakarta EE integration module (see <a href="https://shiro.apache.org/jakarta-ee.html">Jakarta EE Integration</a> for more information)</li>
   <li>SpringBoot 3.x support (SpringBoot 2.x is also supported)</li>
   <li>Automatic form resubmission when session expired (Jakarta EE only)</li>
   </ul>
   <h2>What's Changed</h2>
   <ul>
   <li>[SHIRO-762] Mark <code>SecurityUtils.securityManager</code> as volatile by <a href="https://github.com/boris-petrov"><code>@​boris-petrov</code></a> in <a href="https://redirect.github.com/apache/shiro/pull/218">apache/shiro#218</a></li>
   <li>[SHIRO-765] Upgrade to Apache Pom Parent 23 by <a href="https://github.com/fpapon"><code>@​fpapon</code></a> in <a href="https://redirect.github.com/apache/shiro/pull/222">apache/shiro#222</a></li>
   <li>[SHIRO-766] ignore exception on invalid cookies. by <a href="https://github.com/bmarwell"><code>@​bmarwell</code></a> in <a href="https://redirect.github.com/apache/shiro/pull/225">apache/shiro#225</a></li>
   <li>[SHIRO-764] Add IpFilter for restricting access IP ranges by <a href="https://github.com/mookkiah"><code>@​mookkiah</code></a> in <a href="https://redirect.github.com/apache/shiro/pull/219">apache/shiro#219</a></li>
   <li>SHIRO-708 - Remove deprecated shiro-cas module by <a href="https://github.com/coheigea"><code>@​coheigea</code></a> in <a href="https://redirect.github.com/apache/shiro/pull/152">apache/shiro#152</a></li>
   <li>[SHIRO-770] Remove base64 implementation, keep UTF-8 codec by default. by <a href="https://github.com/bmarwell"><code>@​bmarwell</code></a> in <a href="https://redirect.github.com/apache/shiro/pull/224">apache/shiro#224</a></li>
   <li>[SHIRO-750] update jax-rs dependency to jakarta. Non-Breaking change. by <a href="https://github.com/bmarwell"><code>@​bmarwell</code></a> in <a href="https://redirect.github.com/apache/shiro/pull/207">apache/shiro#207</a></li>
   <li>[SHIRO-750] update jax-rs dependency to jakarta. by <a href="https://github.com/bmarwell"><code>@​bmarwell</code></a> in <a href="https://redirect.github.com/apache/shiro/pull/226">apache/shiro#226</a></li>
   <li>Remove CI profile for 2.0.0 by <a href="https://github.com/fpapon"><code>@​fpapon</code></a> in <a href="https://redirect.github.com/apache/shiro/pull/229">apache/shiro#229</a></li>
   <li>[SHIRO-770] Fix test regression introduced by SHIRO-770. by <a href="https://github.com/bmarwell"><code>@​bmarwell</code></a> in <a href="https://redirect.github.com/apache/shiro/pull/228">apache/shiro#228</a></li>
   <li>[SHIRO-772] Remove PowerMock from EnvironmentLoaderServiceTest.java. by <a href="https://github.com/bmarwell"><code>@​bmarwell</code></a> in <a href="https://redirect.github.com/apache/shiro/pull/230">apache/shiro#230</a></li>
   <li>[SHIRO-773] update groovy for JDK14 builds. by <a href="https://github.com/bmarwell"><code>@​bmarwell</code></a> in <a href="https://redirect.github.com/apache/shiro/pull/231">apache/shiro#231</a></li>
   <li>[SHIRO-775] Excessive logging in jetty ContainerITs by <a href="https://github.com/fpapon"><code>@​fpapon</code></a> in <a href="https://redirect.github.com/apache/shiro/pull/233">apache/shiro#233</a></li>
   <li>[SHIRO-771] Add additional build jobs with various JDKs. by <a href="https://github.com/bmarwell"><code>@​bmarwell</code></a> in <a href="https://redirect.github.com/apache/shiro/pull/227">apache/shiro#227</a></li>
   <li>(doc) Committer Update by <a href="https://github.com/bmarwell"><code>@​bmarwell</code></a> in <a href="https://redirect.github.com/apache/shiro/pull/221">apache/shiro#221</a></li>
   <li>[SHIRO-774] remove ignored prerequisites by <a href="https://github.com/bmarwell"><code>@​bmarwell</code></a> in <a href="https://redirect.github.com/apache/shiro/pull/234">apache/shiro#234</a></li>
   <li>[SHIRO-777] remove powermock. by <a href="https://github.com/bmarwell"><code>@​bmarwell</code></a> in <a href="https://redirect.github.com/apache/shiro/pull/235">apache/shiro#235</a></li>
   <li>[SHIRO-768] Remove the shiro-all module by <a href="https://github.com/fpapon"><code>@​fpapon</code></a> in <a href="https://redirect.github.com/apache/shiro/pull/232">apache/shiro#232</a></li>
   <li>[SHIRO-679] Shiro modules have split packages by <a href="https://github.com/fpapon"><code>@​fpapon</code></a> in <a href="https://redirect.github.com/apache/shiro/pull/236">apache/shiro#236</a></li>
   <li>[SHIRO-776] Update JUnit by <a href="https://github.com/bmarwell"><code>@​bmarwell</code></a> in <a href="https://redirect.github.com/apache/shiro/pull/237">apache/shiro#237</a></li>
   <li>(DOC) - Fix the annotation of setCredentialsMatcher method in AuthenticatingR… by <a href="https://github.com/ramostear"><code>@​ramostear</code></a> in <a href="https://redirect.github.com/apache/shiro/pull/238">apache/shiro#238</a></li>
   <li>[SHIRO-761] Bad OSGi import for javax.annotation in shiro-guice by <a href="https://github.com/fpapon"><code>@​fpapon</code></a> in <a href="https://redirect.github.com/apache/shiro/pull/243">apache/shiro#243</a></li>
   <li>[SHIRO-551] Implement toString() for DelegatingSubject.java. by <a href="https://github.com/bmarwell"><code>@​bmarwell</code></a> in <a href="https://redirect.github.com/apache/shiro/pull/220">apache/shiro#220</a></li>
   <li>[SHIRO-784] Fixed issue where no custom filters are defined in spring (non-boot) apps by <a href="https://github.com/bdemers"><code>@​bdemers</code></a> in <a href="https://redirect.github.com/apache/shiro/pull/244">apache/shiro#244</a></li>
   <li>[SHIRO-778] onInit method on AuthenticatingRealm is called twice by <a href="https://github.com/fpapon"><code>@​fpapon</code></a> in <a href="https://redirect.github.com/apache/shiro/pull/240">apache/shiro#240</a></li>
   <li>[SHIRO-610] Allways create resolver for non-empty IniWebEnvironment by <a href="https://github.com/tbrugz"><code>@​tbrugz</code></a> in <a href="https://redirect.github.com/apache/shiro/pull/242">apache/shiro#242</a></li>
   <li>[SHIRO-398] - Renamed the variable interval to sessionValidationInterval by <a href="https://github.com/vgaur"><code>@​vgaur</code></a> in <a href="https://redirect.github.com/apache/shiro/pull/245">apache/shiro#245</a></li>
   <li>[SHIRO-785] Upgrade to maven-bundle-plugin 5.1.1 by <a href="https://github.com/fpapon"><code>@​fpapon</code></a> in <a href="https://redirect.github.com/apache/shiro/pull/246">apache/shiro#246</a></li>
   <li>[SHIRO-786] Upgrade to Spring 5.2.8.RELEASE and Spring boot 2.3.2.REL… by <a href="https://github.com/fpapon"><code>@​fpapon</code></a> in <a href="https://redirect.github.com/apache/shiro/pull/247">apache/shiro#247</a></li>
   <li>[SHIRO-780] NOTICE files of shiro components don't match NOTICE in so… by <a href="https://github.com/fpapon"><code>@​fpapon</code></a> in <a href="https://redirect.github.com/apache/shiro/pull/239">apache/shiro#239</a></li>
   <li>Add Jenkins file by <a href="https://github.com/fpapon"><code>@​fpapon</code></a> in <a href="https://redirect.github.com/apache/shiro/pull/249">apache/shiro#249</a></li>
   <li>[SHIRO-767] Fixed issue where ClassUtil cannot load the array of Primitive DataType... by <a href="https://github.com/ddddyyyy"><code>@​ddddyyyy</code></a> in <a href="https://redirect.github.com/apache/shiro/pull/248">apache/shiro#248</a></li>
   <li>[SHIRO-740] SslFilter with HTTP Strict Transport Security (HSTS) by <a href="https://github.com/raupachz"><code>@​raupachz</code></a> in <a href="https://redirect.github.com/apache/shiro/pull/55">apache/shiro#55</a></li>
   <li>SHIRO-349 Security: Byte arrays (and other memory) holding sensitive … by <a href="https://github.com/bmarwell"><code>@​bmarwell</code></a> in <a href="https://redirect.github.com/apache/shiro/pull/254">apache/shiro#254</a></li>
   <li>Add Sonarqube quality check by <a href="https://github.com/fpapon"><code>@​fpapon</code></a> in <a href="https://redirect.github.com/apache/shiro/pull/256">apache/shiro#256</a></li>
   <li>Move sonar build step to Java 11 pipeline by <a href="https://github.com/fpapon"><code>@​fpapon</code></a> in <a href="https://redirect.github.com/apache/shiro/pull/258">apache/shiro#258</a></li>
   <li>[SHIRO-793] deleteMe cookie should use the defined &quot;sameSite&quot; by <a href="https://github.com/FredTreg"><code>@​FredTreg</code></a> in <a href="https://redirect.github.com/apache/shiro/pull/257">apache/shiro#257</a></li>
   <li>Update AbstractContainerIT to allow for HTTPS connections Using a pre-generated keystore (master) by <a href="https://github.com/bdemers"><code>@​bdemers</code></a> in <a href="https://redirect.github.com/apache/shiro/pull/260">apache/shiro#260</a></li>
   <li>[No JIRA] Fix inefficient iterators by <a href="https://github.com/TomMD"><code>@​TomMD</code></a> in <a href="https://redirect.github.com/apache/shiro/pull/250">apache/shiro#250</a></li>
   <li>[SHIRO-789] Add SameSite option to AbstractShiroWebConfiguration.buildCookie by <a href="https://github.com/bmarwell"><code>@​bmarwell</code></a> in <a href="https://redirect.github.com/apache/shiro/pull/251">apache/shiro#251</a></li>
   <li>[CI] Update maven and jdk labels by <a href="https://github.com/fpapon"><code>@​fpapon</code></a> in <a href="https://redirect.github.com/apache/shiro/pull/261">apache/shiro#261</a></li>
   </ul>
   <!-- raw HTML omitted -->
   </blockquote>
   <p>... (truncated)</p>
   </details>
   <details>
   <summary>Changelog</summary>
   <p><em>Sourced from <a href="https://github.com/apache/shiro/blob/main/RELEASE-NOTES">org.apache.shiro:shiro-core's changelog</a>.</em></p>
   <blockquote>
   <h1>2.0.0</h1>
   <p>###########################################################</p>
   <p>Improvement</p>
   <pre><code>[SHIRO-290] Implement bcrypt and argon2 KDF algorithms
   </code></pre>
   <h2>Backwards Incompatible Changes</h2>
   <ul>
   <li>Changed default DefaultPasswordService.java algorithm to &quot;Argon2id&quot;.</li>
   <li>PasswordService.encryptPassword(Object plaintext) will now throw a NullPointerException on null parameter.
   It was never specified how this method would behave.</li>
   <li>Made salt non-nullable.</li>
   <li>Removed methods in PasswordMatcher.</li>
   </ul>
   <p>###########################################################</p>
   <h1>1.7.1</h1>
   <p>###########################################################</p>
   <p>Bug</p>
   <pre><code>[SHIRO-797] - Shiro 1.7.0 is lower than using springboot version 2.0.7 dependency error
   </code></pre>
   <p>###########################################################</p>
   <h1>1.7.0</h1>
   <p>###########################################################</p>
   <p>Bug</p>
   <pre><code>[SHIRO-767] - org.apache.shiro.util.ClassUtil cannot load the array of Primitive DataType when use undertow as web container
   [SHIRO-792] - ShiroWebFilterConfiguration seems to conflict with other FilterRegistrationBean
   </code></pre>
   <p>New Feature</p>
   <pre><code>[SHIRO-789] - Also add cookie SameSite option to Spring
   </code></pre>
   <p>Improvement</p>
   <pre><code>[SHIRO-740] - SslFilter with HTTP Strict Transport Security (HSTS)
   [SHIRO-794] - Add system property to enable backslash path normalization
   [SHIRO-795] - Disable session path rewriting by default
   </code></pre>
   <p>Task</p>
   <pre><code>[SHIRO-793] - deleteMe cookie should use the defined &quot;sameSite&quot;
   </code></pre>
   <!-- raw HTML omitted -->
   </blockquote>
   <p>... (truncated)</p>
   </details>
   <details>
   <summary>Commits</summary>
   <ul>
   <li><a href="https://github.com/apache/shiro/commit/ef7117b4a81095b705b6e07acc8bf889d547fc9a"><code>ef7117b</code></a> [maven-release-plugin] prepare release shiro-root-2.0.0</li>
   <li><a href="https://github.com/apache/shiro/commit/d2afa85a075691301033f201eec26265fd93c4cf"><code>d2afa85</code></a> Merge pull request <a href="https://redirect.github.com/apache/shiro/issues/1320">#1320</a> from apache/dependabot/maven/com.github.siom79.japic...</li>
   <li><a href="https://github.com/apache/shiro/commit/879c6a703f0401a2f09e267e4a34d5ccd3ce736f"><code>879c6a7</code></a> Merge pull request <a href="https://redirect.github.com/apache/shiro/issues/1319">#1319</a> from apache/dependabot/maven/tomcat.version-10.1.19</li>
   <li><a href="https://github.com/apache/shiro/commit/e8fd2a90b31f61c46eec936fe65149d43beb1a3c"><code>e8fd2a9</code></a> Merge pull request <a href="https://redirect.github.com/apache/shiro/issues/1318">#1318</a> from apache/dependabot/maven/com.flowlogix-flowlogix...</li>
   <li><a href="https://github.com/apache/shiro/commit/bcbb087ccf5149eec37b74f1fc97fd4fc6f9663a"><code>bcbb087</code></a> build(deps): bump com.github.siom79.japicmp:japicmp-maven-plugin</li>
   <li><a href="https://github.com/apache/shiro/commit/02ca3fb0d83b96d09ff913da9197c00423671284"><code>02ca3fb</code></a> build(deps-dev): bump tomcat.version from 10.1.18 to 10.1.19</li>
   <li><a href="https://github.com/apache/shiro/commit/a385227a1b5a4203b6ee847c8d1d053c99f56f3a"><code>a385227</code></a> build(deps): bump com.flowlogix:flowlogix-jee from 5.5.2 to 5.5.3</li>
   <li><a href="https://github.com/apache/shiro/commit/8ecf148f08ec4becf8d45f38aa1f6b74f49cfdfe"><code>8ecf148</code></a> Merge pull request <a href="https://redirect.github.com/apache/shiro/issues/1314">#1314</a> from apache/dependabot/maven/com.github.siom79.japic...</li>
   <li><a href="https://github.com/apache/shiro/commit/6d99d22b49f12773b9ae64e21ea0c6dd3977b08d"><code>6d99d22</code></a> Merge pull request <a href="https://redirect.github.com/apache/shiro/issues/1313">#1313</a> from apache/dependabot/maven/bytebuddy.version-1.14.12</li>
   <li><a href="https://github.com/apache/shiro/commit/acec94d3989a46238f9913c238baec6d5a1a2086"><code>acec94d</code></a> build(deps): bump com.github.siom79.japicmp:japicmp-maven-plugin</li>
   <li>Additional commits viewable in <a href="https://github.com/apache/shiro/compare/shiro-root-1.13.0...shiro-root-2.0.0">compare view</a></li>
   </ul>
   </details>
   <br />
   
   
   [![Dependabot compatibility score](https://dependabot-badges.githubapp.com/badges/compatibility_score?dependency-name=org.apache.shiro:shiro-core&package-manager=maven&previous-version=1.13.0&new-version=2.0.0)](https://docs.github.com/en/github/managing-security-vulnerabilities/about-dependabot-security-updates#about-compatibility-scores)
   
   Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting `@dependabot rebase`.
   
   [//]: # (dependabot-automerge-start)
   [//]: # (dependabot-automerge-end)
   
   ---
   
   <details>
   <summary>Dependabot commands and options</summary>
   <br />
   
   You can trigger Dependabot actions by commenting on this PR:
   - `@dependabot rebase` will rebase this PR
   - `@dependabot recreate` will recreate this PR, overwriting any edits that have been made to it
   - `@dependabot merge` will merge this PR after your CI passes on it
   - `@dependabot squash and merge` will squash and merge this PR after your CI passes on it
   - `@dependabot cancel merge` will cancel a previously requested merge and block automerging
   - `@dependabot reopen` will reopen this PR if it is closed
   - `@dependabot close` will close this PR and stop Dependabot recreating it. You can achieve the same result by closing it manually
   - `@dependabot show <dependency name> ignore conditions` will show all of the ignore conditions of the specified dependency
   - `@dependabot ignore this major version` will close this PR and stop Dependabot creating any more for this major version (unless you reopen the PR or upgrade to it yourself)
   - `@dependabot ignore this minor version` will close this PR and stop Dependabot creating any more for this minor version (unless you reopen the PR or upgrade to it yourself)
   - `@dependabot ignore this dependency` will close this PR and stop Dependabot creating any more for this dependency (unless you reopen the PR or upgrade to it yourself)
   
   
   </details>


-- 
This is an automated message from the Apache Git Service.
To respond to the message, please log on to GitHub and use the
URL above to go to the specific comment.

To unsubscribe, e-mail: commits-unsubscribe@camel.apache.org

For queries about this service, please contact Infrastructure at:
users@infra.apache.org


Re: [PR] Bump org.apache.shiro:shiro-core from 1.13.0 to 2.0.0 [camel]

Posted by "github-actions[bot] (via GitHub)" <gi...@apache.org>.
github-actions[bot] commented on PR #13344:
URL: https://github.com/apache/camel/pull/13344#issuecomment-1970519090

   :star2: Thank you for your contribution to the Apache Camel project! :star2: 
   
   :robot: CI automation will test this PR automatically.
   
   :camel: Apache Camel Committers, please review the following items:
   
   * First-time contributors **require MANUAL approval** for the GitHub Actions to run
   
   * You can use the command `/component-test (camel-)component-name1 (camel-)component-name2..` to request a test from the test bot.
   
   * You can label PRs using `build-all`, `build-dependents`, `skip-tests` and `test-dependents` to fine-tune the checks executed by this PR.
   
   * Build and test logs are available in the Summary page. **Only** [Apache Camel committers](https://camel.apache.org/community/team/#committers) have access to the summary. 
   
   * :warning: Be careful when sharing logs. Review their contents before sharing them publicly.


-- 
This is an automated message from the Apache Git Service.
To respond to the message, please log on to GitHub and use the
URL above to go to the specific comment.

To unsubscribe, e-mail: commits-unsubscribe@camel.apache.org

For queries about this service, please contact Infrastructure at:
users@infra.apache.org


Re: [PR] Bump org.apache.shiro:shiro-core from 1.13.0 to 2.0.0 [camel]

Posted by "dependabot[bot] (via GitHub)" <gi...@apache.org>.
dependabot[bot] commented on PR #13344:
URL: https://github.com/apache/camel/pull/13344#issuecomment-1972721988

   OK, I won't notify you again about this release, but will get in touch when a new version is available. If you'd rather skip all updates until the next major or minor version, let me know by commenting `@dependabot ignore this major version` or `@dependabot ignore this minor version`. You can also ignore all major, minor, or patch releases for a dependency by adding an [`ignore` condition](https://docs.github.com/en/code-security/supply-chain-security/configuration-options-for-dependency-updates#ignore) with the desired `update_types` to your config file.
   
   If you change your mind, just re-open this PR and I'll resolve any conflicts on it.


-- 
This is an automated message from the Apache Git Service.
To respond to the message, please log on to GitHub and use the
URL above to go to the specific comment.

To unsubscribe, e-mail: commits-unsubscribe@camel.apache.org

For queries about this service, please contact Infrastructure at:
users@infra.apache.org


Re: [PR] Bump org.apache.shiro:shiro-core from 1.13.0 to 2.0.0 [camel]

Posted by "oscerd (via GitHub)" <gi...@apache.org>.
oscerd closed pull request #13344: Bump org.apache.shiro:shiro-core from 1.13.0 to 2.0.0
URL: https://github.com/apache/camel/pull/13344


-- 
This is an automated message from the Apache Git Service.
To respond to the message, please log on to GitHub and use the
URL above to go to the specific comment.

To unsubscribe, e-mail: commits-unsubscribe@camel.apache.org

For queries about this service, please contact Infrastructure at:
users@infra.apache.org


Re: [PR] Bump org.apache.shiro:shiro-core from 1.13.0 to 2.0.0 [camel]

Posted by "oscerd (via GitHub)" <gi...@apache.org>.
oscerd commented on PR #13344:
URL: https://github.com/apache/camel/pull/13344#issuecomment-1972721939

   Requires manual update.


-- 
This is an automated message from the Apache Git Service.
To respond to the message, please log on to GitHub and use the
URL above to go to the specific comment.

To unsubscribe, e-mail: commits-unsubscribe@camel.apache.org

For queries about this service, please contact Infrastructure at:
users@infra.apache.org


Re: [PR] Bump org.apache.shiro:shiro-core from 1.13.0 to 2.0.0 [camel]

Posted by "github-actions[bot] (via GitHub)" <gi...@apache.org>.
github-actions[bot] commented on PR #13344:
URL: https://github.com/apache/camel/pull/13344#issuecomment-1972716029

   :robot: The Apache Camel test robot will run the tests for you :+1:


-- 
This is an automated message from the Apache Git Service.
To respond to the message, please log on to GitHub and use the
URL above to go to the specific comment.

To unsubscribe, e-mail: commits-unsubscribe@camel.apache.org

For queries about this service, please contact Infrastructure at:
users@infra.apache.org


Re: [PR] Bump org.apache.shiro:shiro-core from 1.13.0 to 2.0.0 [camel]

Posted by "oscerd (via GitHub)" <gi...@apache.org>.
oscerd commented on PR #13344:
URL: https://github.com/apache/camel/pull/13344#issuecomment-1972715291

   /component-test shiro


-- 
This is an automated message from the Apache Git Service.
To respond to the message, please log on to GitHub and use the
URL above to go to the specific comment.

To unsubscribe, e-mail: commits-unsubscribe@camel.apache.org

For queries about this service, please contact Infrastructure at:
users@infra.apache.org