Skip to content

Bump org.apache.shiro:shiro-core from 1.13.0 to 2.0.0#18430

Merged
kroepke merged 7 commits into
masterfrom
dependabot/maven/org.apache.shiro-shiro-core-2.0.0
Mar 5, 2024
Merged

Bump org.apache.shiro:shiro-core from 1.13.0 to 2.0.0#18430
kroepke merged 7 commits into
masterfrom
dependabot/maven/org.apache.shiro-shiro-core-2.0.0

Conversation

@dependabot

@dependabot dependabot Bot commented on behalf of github Feb 29, 2024

Copy link
Copy Markdown
Contributor

Bumps org.apache.shiro:shiro-core from 1.13.0 to 2.0.0.

Release notes

Sourced from org.apache.shiro:shiro-core's releases.

Apache Shiro 2.0.0

What's new Highlights

  • Java 11 is the minimum supported JVM version
  • Jakarta EE 10 support (Java/Jakarta EE 8 is also supported)
  • New Jakarta EE integration module (see Jakarta EE Integration for more information)
  • SpringBoot 3.x support (SpringBoot 2.x is also supported)
  • Automatic form resubmission when session expired (Jakarta EE only)

What's Changed

... (truncated)

Changelog

Sourced from org.apache.shiro:shiro-core's changelog.

2.0.0

###########################################################

Improvement

[SHIRO-290] Implement bcrypt and argon2 KDF algorithms

Backwards Incompatible Changes

  • Changed default DefaultPasswordService.java algorithm to "Argon2id".
  • PasswordService.encryptPassword(Object plaintext) will now throw a NullPointerException on null parameter. It was never specified how this method would behave.
  • Made salt non-nullable.
  • Removed methods in PasswordMatcher.

###########################################################

1.7.1

###########################################################

Bug

[SHIRO-797] - Shiro 1.7.0 is lower than using springboot version 2.0.7 dependency error

###########################################################

1.7.0

###########################################################

Bug

[SHIRO-767] - org.apache.shiro.util.ClassUtil cannot load the array of Primitive DataType when use undertow as web container
[SHIRO-792] - ShiroWebFilterConfiguration seems to conflict with other FilterRegistrationBean

New Feature

[SHIRO-789] - Also add cookie SameSite option to Spring

Improvement

[SHIRO-740] - SslFilter with HTTP Strict Transport Security (HSTS)
[SHIRO-794] - Add system property to enable backslash path normalization
[SHIRO-795] - Disable session path rewriting by default

Task

[SHIRO-793] - deleteMe cookie should use the defined "sameSite"

... (truncated)

Commits
  • ef7117b [maven-release-plugin] prepare release shiro-root-2.0.0
  • d2afa85 Merge pull request #1320 from apache/dependabot/maven/com.github.siom79.japic...
  • 879c6a7 Merge pull request #1319 from apache/dependabot/maven/tomcat.version-10.1.19
  • e8fd2a9 Merge pull request #1318 from apache/dependabot/maven/com.flowlogix-flowlogix...
  • bcbb087 build(deps): bump com.github.siom79.japicmp:japicmp-maven-plugin
  • 02ca3fb build(deps-dev): bump tomcat.version from 10.1.18 to 10.1.19
  • a385227 build(deps): bump com.flowlogix:flowlogix-jee from 5.5.2 to 5.5.3
  • 8ecf148 Merge pull request #1314 from apache/dependabot/maven/com.github.siom79.japic...
  • 6d99d22 Merge pull request #1313 from apache/dependabot/maven/bytebuddy.version-1.14.12
  • acec94d build(deps): bump com.github.siom79.japicmp:japicmp-maven-plugin
  • Additional commits viewable in compare view

Dependabot compatibility score

You can trigger a rebase of this PR by commenting @dependabot rebase.


Dependabot commands and options

You can trigger Dependabot actions by commenting on this PR:

  • @dependabot rebase will rebase this PR
  • @dependabot recreate will recreate this PR, overwriting any edits that have been made to it
  • @dependabot merge will merge this PR after your CI passes on it
  • @dependabot squash and merge will squash and merge this PR after your CI passes on it
  • @dependabot cancel merge will cancel a previously requested merge and block automerging
  • @dependabot reopen will reopen this PR if it is closed
  • @dependabot close will close this PR and stop Dependabot recreating it. You can achieve the same result by closing it manually
  • @dependabot show <dependency name> ignore conditions will show all of the ignore conditions of the specified dependency
  • @dependabot ignore this major version will close this PR and stop Dependabot creating any more for this major version (unless you reopen the PR or upgrade to it yourself)
  • @dependabot ignore this minor version will close this PR and stop Dependabot creating any more for this minor version (unless you reopen the PR or upgrade to it yourself)
  • @dependabot ignore this dependency will close this PR and stop Dependabot creating any more for this dependency (unless you reopen the PR or upgrade to it yourself)

Bumps [org.apache.shiro:shiro-core](https://github.com/apache/shiro) from 1.13.0 to 2.0.0.
- [Release notes](https://github.com/apache/shiro/releases)
- [Changelog](https://github.com/apache/shiro/blob/main/RELEASE-NOTES)
- [Commits](apache/shiro@shiro-root-1.13.0...shiro-root-2.0.0)

---
updated-dependencies:
- dependency-name: org.apache.shiro:shiro-core
  dependency-type: direct:production
  update-type: version-update:semver-major
...

Signed-off-by: dependabot[bot] <support@github.com>
@dependabot dependabot Bot added dependencies Pull requests that update a dependency file maven labels Feb 29, 2024
@kroepke kroepke self-assigned this Mar 4, 2024
@kroepke kroepke requested review from a team, bernd and thll and removed request for bernd and thll March 5, 2024 12:11
@kroepke

kroepke commented Mar 5, 2024

Copy link
Copy Markdown
Member

Tested this with MongoDB users, permissions, shares, and a FusionAuth OIDC authenticator.

All works as expected.

@kroepke kroepke removed the request for review from a team March 5, 2024 12:28
@kroepke kroepke requested a review from a team March 5, 2024 13:18
@kroepke kroepke merged commit df42c81 into master Mar 5, 2024
@kroepke kroepke deleted the dependabot/maven/org.apache.shiro-shiro-core-2.0.0 branch March 5, 2024 15:38
janheise pushed a commit that referenced this pull request Mar 7, 2024
* Bump org.apache.shiro:shiro-core from 1.13.0 to 2.0.0

Bumps [org.apache.shiro:shiro-core](https://github.com/apache/shiro) from 1.13.0 to 2.0.0.
- [Release notes](https://github.com/apache/shiro/releases)
- [Changelog](https://github.com/apache/shiro/blob/main/RELEASE-NOTES)
- [Commits](apache/shiro@shiro-root-1.13.0...shiro-root-2.0.0)

---
updated-dependencies:
- dependency-name: org.apache.shiro:shiro-core
  dependency-type: direct:production
  update-type: version-update:semver-major
...

Signed-off-by: dependabot[bot] <support@github.com>

* use common-digest MD5/hex functions instead of shiro's versions

remove long-time unused classes that referenced removed shiro classes

* add changelog

* update import package for LifecycleUtils

* Use static Hex.decodeHex instead of constructing a new instance

---------

Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
Co-authored-by: Kay Roepke <kroepke@googlemail.com>
Co-authored-by: Bernd Ahlers <bernd@graylog.com>
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

dependencies Pull requests that update a dependency file maven

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants